MITRE ATT&CK G1004
LAPSUS$ Group
View MITRE Group Page ↗
Aliases: DEV-0537, Strawberry Tempest
Official Attribution Source: DHS Cyber Safety Review Board (CSRB) Report on LAPSUS$
Key Facts
Jurisdiction
Transnational (UK / Brazil)
Geographic origin
Cases
0
Prosecution matters
Defendants
0
Indicted individuals
Sanctions
0
OFAC designations
- Attributed Country: Transnational (UK / Brazil).
- ATT&CK Group Reference: G1004 (LAPSUS$ Group).
- Linked to 0 primary court prosecution records.
- Identified 0 individually charged operatives.
Prosecution Cases Attributed to This Actor
OPERATIONAL DEFENSE
Targeted Defensive Hardening for LAPSUS$ Group
Primary Initial Access Defense
Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.
Lateral Movement Interception
Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.