Threat Intelligence Tarot
cups · 1
Criminal (UK/Brazil, mostly teenagers)
G1004★★★★★
risk 4/5
✦ The Jester ✦
Lapsus$
DEV-0537 · Strawberry Tempest
MicrosoftNvidiaSamsungOktaRockstar GamesT-Mobile
Active ~2021–2022 · Data theft for extortion, Notoriety, Corporate embarrassment
The Jester is a teenager who called Microsoft's help desk. Then Samsung's. Then Nvidia's. Lapsus$ discovered that corporations spending millions on technical security had left their phone lines and help desks completely open - and that social engineering could defeat any MFA if someone was willing to make enough calls.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
Notable Operations
- ◆Nvidia source code theft - 1TB including DLSS (2022)
- ◆Samsung source code and biometric data theft
- ◆Microsoft Azure DevOps breach - Bing and Cortana source code
- ◆Rockstar Games GTA VI pre-release footage leak
- ◆Okta breach - customer support system access
Defenses
- ▸Phishing-resistant MFA (FIDO2) - not SMS or push notificationNIST SP 800-63B ↗
- ▸Help desk identity verification procedures beyond knowledge-based authNIST CSF: PR.AC ↗
- ▸Insider threat monitoring on privileged accounts and code repositoriesNIST CSF: DE.CM ↗
- ▸Conditional access policies for cloud service accessCIS Control 6 ↗
Reversed: Their Weakness
Multiple Lapsus$ members were identified, arrested, and prosecuted - many were teenagers operating without operational security. Their notoriety-seeking behavior, bragging in public Telegram channels, and recruitment of insiders provided law enforcement with extensive evidence.
Share this adversary profile
Compare →swipe to browse
Related Adversaries
Data sourced from MITRE ATT&CK. For educational purposes.