Detect, Respond, Protect
See how the global Huntress SOC can augment your team
with 24/7 coverage and unmatched human expertise.
Start your free trial today.
Slippy Spider, also known as Lapsus$, is a cybercriminal group that emerged around late 2021, quickly growing notorious for their brazen data extortion tactics and disruptive attacks on large corporations and governments. Known for targeting prominent industries, this group uses creative and unconventional infiltration techniques that exploit both technical vulnerabilities and social engineering weaknesses.
Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.
The group primarily aims to exfiltrate sensitive corporate data for ransom payments. Their brazen attitude often involves leaking stolen information to pressure victims.
Social engineering (e.g., phishing employees to gain login credentials)
Exploiting weak protections in multifactor authentication (MFA) systems
Buying insider access from disgruntled employees
Slippy Spider has been known to use SIM-swapping techniques, breach collaboration tools (e.g., Slack, GitHub), and even publicize their attacks through social media channels—mocking victims.
Organizations should monitor for:
Fancy Bear targets include:
Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.
Microsoft: Breached GitHub repositories to access source code for internal projects.
NVIDIA: Stole sensitive employee data and proprietary designs, demanding ransom while leaking intel online.
Okta: Compromised a customer support system affecting thousands of clients.
Strengthen Access Controls: Implement robust MFA solutions and regularly audit account permissions.
Employee Training: Educate staff on phishing risks and how to spot social engineering schemes.
Monitor Credentials: Use tools like Huntress ITDR to identify compromised credentials or unusual login behaviors.
Incident Response: Deploy threat detection and response tools to detect and contain breaches early.
Law enforcement efforts have struck notable blows against Slippy Spider. A London-based teenager believed to be a key figure was arrested in early 2022, alongside other suspects in Brazil. These arrests underscore international cooperation against cybercrime, though the fate of Slippy Spider remains uncertain.
Notable developments include the U.S. indictment of GRU-affiliated officers in 2018. Despite these measures, Fancy Bear remains operational, emphasizing the challenges of deterring state-sponsored cyber actors.