LazyScripter
Overview
LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.
Naming & attribution
LazyScripter is tracked under 1 names across the industry. It uses 20 documented ATT&CK techniques — more than 53% of the 174 groups tracked here. Activity attributed since at least 2018.
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
Malware families with current indicators
2 families attributed to LazyScripter, carrying 3,121 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- Remcos 2,964 indicators
- Koadic 157 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
TTPs — 20 techniques across 6 tactics
Resource Development
-
T1583.001Domains -
T1583.006Web Services -
T1588.001Malware -
T1608.001Upload Malware
Initial Access
-
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link
Execution
-
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1059.005Visual Basic -
T1059.007JavaScript -
T1204.001Malicious Link -
T1204.002Malicious File
Persistence
-
T1547.001Registry Run Keys / Startup Folder
Stealth
-
T1027.010Command Obfuscation -
T1036Masquerading -
T1218.005Mshta -
T1218.011Rundll32
Command and Control
-
T1071.004DNS -
T1102Web Service -
T1105Ingress Tool Transfer
Tools & malware (7)
Remcos · QuasarRAT · njRAT · ngrok · Empire · Koadic · KOCTOPUS
Reporting (1)
- LazyScripter: From Empire to double RAT — Jazi, H