NEW: Group Profiler — instant APT intel lookup. Try it →
Emblem illustrating the LazyScripter threat group

LazyScripter

Overview

LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.

Naming & attribution

It uses 20 documented ATT&CK techniques — more than 53% of the 174 groups tracked here. Activity attributed since at least 2018.

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • TA2541 — 13 shared techniques (37% overlap)
  • TA505 — 14 shared techniques (35% overlap)
  • Confucius — 10 shared techniques (34% overlap)
  • Molerats — 9 shared techniques (33% overlap)
  • WIRTE — 11 shared techniques (31% overlap)
  • TA551 — 8 shared techniques (31% overlap)

Malware families with tracked indicators

2 families attributed to LazyScripter, with 556 deduplicated indicators observed across abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL over the corpus's window (up to three years, as of 2026-09-26). MITRE documents what a group does; these are the indicators its malware families have surfaced in that window.

  • Remcos 475 indicators
  • Koadic 81 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

TTPs — 20 techniques across 6 tactics

Resource Development

Initial Access

Execution

Persistence

Stealth

Command and Control

Tools & malware (7)

Remcos · QuasarRAT · njRAT · ngrok · Empire · Koadic · KOCTOPUS

Reporting (1)