Threat Actor Unknown origin
LAPSUS
Also known as: LAPSUS$ · DEV-0537 · SLIPPY SPIDER · Strawberry Tempest · UNC3661 · Lapsus
An actor group conducting large-scale social engineering and extortion campaign against multiple organizations with some seeing evidence of destructive elements.
Indicators of Compromise 8
MITRE ATT&CK TTPs 11
T1059.001 T1071 T1071.001 T1078 T1081 T1090 T1098 T1102 T1133 T1553 T1566
PowerShell
Execution
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
T1081
Proxy
Command And Control
Account Manipulation
Persistence
Web Service
Command And Control
External Remote Services
Persistence
Subvert Trust Controls
Defense Evasion
Phishing
Initial Access
Source Articles
Cloud Threat Highlights: H1 2026
In H1 2026, a surge in cloud-based threats was driven by aggressive software supply-chain attacks, particularly by the group TeamPCP, which compromised developer toolchains across npm, PyPI, and VSCode extensions to steal credentials and propagate across cloud environments. TeamPCP's malware evolved to exploit CI misconfigurations, extract OIDC tokens, and deploy wipers with Dune-themed taunts. North Korea's UNC1069 conducted parallel campaigns, trojanizing the axios package and compromising over 140 @mastra-related packages. The open-sourced Shai-Hulud worm enabled follow-on attacks like IronWorm, which used Rust-based binaries and eBPF rootkits for stealth. A new extortion group, JINX-0163, emerged, targeting cloud identities across AWS, Azure, and GCP to steal secrets and enable ransom threats via the alias 'FulcrumSec'.
wiz
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
A threat actor tracked as O-UNC-066 is conducting vishing attacks to trick Microsoft 365 users into enrolling attacker-controlled passkeys through a phishing kit that mimics the legitimate Microsoft Entra passkey enrollment process. The attackers register domains with 'passkey' in the name and use voice calls to socially engineer victims into following a fake enrollment flow, ultimately granting unauthorized access to their accounts. The phishing kit is operator-controlled and adapts in real time to the victim's MFA method, allowing the attacker to capture credentials and approve passkey registration. This campaign targets multiple industries and abuses Microsoft's passkey adoption initiative as a social engineering lure.
hacker-news ·1mo ago