Threat Intelligence Tarot
cups · 1
Criminal (UK/Brazil, mostly teenagers)
G1004★★★★★
risk 4/5
✦ The Jester ✦
Lapsus$
DEV-0537 · Strawberry Tempest
MicrosoftNvidiaSamsungOktaRockstar GamesT-Mobile
Active ~2021–2022 · Data theft for extortion, Notoriety, Corporate embarrassment
The Jester is a teenager who called Microsoft's help desk. Then Samsung's. Then Nvidia's. Lapsus$ discovered that corporations spending millions on technical security had left their phone lines and help desks completely open - and that social engineering could defeat any MFA if someone was willing to make enough calls.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
Notable Operations
- ◆Nvidia source code theft - 1TB including DLSS (2022)
- ◆Samsung source code and biometric data theft
- ◆Microsoft Azure DevOps breach - Bing and Cortana source code
- ◆Rockstar Games GTA VI pre-release footage leak
- ◆Okta breach - customer support system access
Defenses
- ▸Phishing-resistant MFA (FIDO2) - not SMS or push notificationNIST SP 800-63B ↗
- ▸Help desk identity verification procedures beyond knowledge-based authNIST CSF: PR.AC ↗
- ▸Insider threat monitoring on privileged accounts and code repositoriesNIST CSF: DE.CM ↗
- ▸Conditional access policies for cloud service accessCIS Control 6 ↗
Reversed: Their Weakness
Multiple Lapsus$ members were identified, arrested, and prosecuted - many were teenagers operating without operational security. Their notoriety-seeking behavior, bragging in public Telegram channels, and recruitment of insiders provided law enforcement with extensive evidence.
Share this adversary profile
swipe to browse
Related Adversaries
Data sourced from MITRE ATT&CK. For educational purposes.