NEW: Group Profiler — instant APT intel lookup. Try it →

LazyScripter

Overview

LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.

Naming & attribution

LazyScripter is tracked under 1 names across the industry. It uses 20 documented ATT&CK techniques — more than 53% of the 174 groups tracked here. Activity attributed since at least 2018.

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • TA2541 — 13 shared techniques (37% overlap)
  • TA505 — 14 shared techniques (35% overlap)
  • Confucius — 10 shared techniques (34% overlap)
  • Molerats — 9 shared techniques (33% overlap)
  • WIRTE — 11 shared techniques (31% overlap)
  • TA551 — 8 shared techniques (31% overlap)

Malware families with current indicators

2 families attributed to LazyScripter, carrying 3,121 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Remcos 2,964 indicators
  • Koadic 157 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

TTPs — 20 techniques across 6 tactics

Resource Development

Initial Access

Execution

Persistence

Stealth

Command and Control

Tools & malware (7)

Remcos · QuasarRAT · njRAT · ngrok · Empire · Koadic · KOCTOPUS

Reporting (1)