Elsevier Evolve, ClinicalPharmacology, and GSDD APIs Hijacked: LAPSUS$ Redirect Campaign
LAPSUS$ hijacked Elsevier education and clinical APIs, redirecting users to extortion splash pages.
Sorami Consulting reports that users and systems connecting to Elsevier Evolve, Sherpath, and ClinicalPharmacology are being redirected to extortion splash pages tied to LAPSUS$. The redirects point to domains including lapsus.ar.io and lapsus.bz. Public discussion describes nursing and medical students locked out of exams and simulation charting. The report also says GSDD APIs were hijacked in the same campaign.
- Elsevier Evolve, Sherpath, and ClinicalPharmacology connections redirect to LAPSUS$ pages.
- Extortion splash pages use domains including lapsus.ar.io and lapsus.bz.
- Nursing and medical students report lockouts from exams and simulation charting.
- The campaign also names hijacked GSDD APIs.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | lapsus.ar.io | splash pages tied to LAPSUS$ (pointing to domains including lapsus[.]ar[.]io and lapsus[.]bz). While public discussion on Reddit is |
| domain | lapsus.bz | LAPSUS$ (pointing to domains including lapsus[.]ar[.]io and lapsus[.]bz). While public discussion on Reddit is dominated by nursi |
Sorami Consulting reports: Users and systems trying to connect to Elsevier Evolve, Sherpath, and ClinicalPharmacology are being redirected to extortion splash pages tied to LAPSUS$ (pointing to domains including lapsus[.]ar[.]io and lapsus[.]bz). While public discussion on Reddit is dominated by nursing and medical students locked out of exams and simulation charting, the real blast radius... Source
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at databreaches.net.