logo

Hardening your cloud environment against LAPSUS$-like threat actors

ID: fa826965-d360-5d6a-b35e-cce8a9ed70df

STIX ID: report--fa826965-d360-5d6a-b35e-cce8a9ed70df

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2022-03-26

Date Updated: 2026-05-01

...
...

This Wiz Research blogpost analyzes LAPSUS$’s cloud-focused extortion activity—outlining a three-stage attack flow (credential compromise, exploiting exposed secrets/unpatched apps for privilege escalation, and pivoting to internal cloud resources for data exfiltration)—notes usage of tooling such as the Redline stealer, and provides prioritized, actionable defenses (MFA, least privilege, secret management, patching, VM hardening) along with Wiz-specific detection and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.