LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.(Citation: MalwareBytes LazyScripter Feb 2021)
Executive Summary
LazyScripter is a threat group primarily targeting the aviation sector since at least 2018, employing open-source tools such as njRAT and KOCTOPUS. Their tactics include spearphishing attacks using malicious links and attachments, leveraging JavaScript and PowerShell for execution.
Goals & Targeting
LazyScripter targets the airline industry due to its access to sensitive data and potential for disruption. The group likely aims to extract financial information, intellectual property, or disrupt operations for competitive advantage or monetary gains.
Enhanced Description
LazyScripter has consistently targeted the airline industry, indicating a strategic focus on sectors with sensitive data and potential operational disruption. They exploit open-source tools to maintain stealth and persistence, employing techniques like obfuscation and web service abuse. Their long-term presence suggests a capability for sustained campaigns aiming to achieve financial gain or espionage objectives.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
LazyScripter conducts targeted campaigns against airlines, utilizing njRAT and KOCTOPUS for long-term access. Their activities suggest a focus on data exfiltration and system disruption, with sustained operations potentially across multiple years.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in targeting methods and toolset, while gaps remain in understanding specific campaigns and exact motivations. Additional data on campaign details and long-term objectives would improve the intelligence picture.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
20
Techniques
2
Tools
0
Campaigns
0
IOCs
0
Observed Data
6
Tactics