Microsoft Shares Details On Lapsus$ Hacking Operations

Share post:

Microsoft has uncovered the activities of Lapsus$, a relatively new hacking group conducting cyberattacks against organizations.

According to Microsoft, Lapsus$ dubbed DEV-0537 uses an extortion and destruction model of attack. This model does not rely on ransomware payloads.

The group employs different social engineering schemes to lure potential victims. This includes phone-based social engineering via SIM-swapping and compromising an individual’s personal or private accounts.

Other tactics include deceiving the company’s support representatives into divulging secrets and carrying out an alliance with employees to gain access to account credentials and MFA details.

The group also purchases credentials and tokens from forums on the Dark Web, scans public code repositories for exposed credentials, and uses a password stealer known as Redline to capture passwords and tokens.

Organizations are advised to protect themselves by requiring MFA for all users, avoiding telephone-based and SMS-based MFA, using Azure AD password protection, and using other password authentication tools.

Others include reviewing their VPN authentication, monitoring and reviewing their cloud security, educating all employees about social engineering attacks, and setting up security processes in response to possible Lapsus$ intrusions.

For more information, read the original story in TechRepublic.

SUBSCRIBE NOW

Related articles

Hashtag Trending for World Password Day, Thursday, May 2nd, 2024

Security firm Okta warns of an unprecendented password stuffing attack that is piggybacking on regular user’s mobile and...

Google Chrome’s new post-quantum cryptography causes connection issues

The latest update to Google Chrome, version 124, which integrates a new quantum-resistant encryption mechanism, has led to...

UK legislation bans weak passwords

Starting Monday, the UK will enforce new laws banning the sale of devices with weak default passwords such...

Massive Credential Stuffing attack exploits home devices

Okta, a leading authentication service, is raising alarms over a massive credential-stuffing attack that cleverly disguises fraudulent login...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways