Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors LazyScripter

Description

LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.(Citation: MalwareBytes LazyScripter Feb 2021)

AI Analysis

· 1 week ago

Executive Summary

LazyScripter is a threat group primarily targeting the aviation sector since at least 2018, employing open-source tools such as njRAT and KOCTOPUS. Their tactics include spearphishing attacks using malicious links and attachments, leveraging JavaScript and PowerShell for execution.

Goals & Targeting

LazyScripter targets the airline industry due to its access to sensitive data and potential for disruption. The group likely aims to extract financial information, intellectual property, or disrupt operations for competitive advantage or monetary gains.

Enhanced Description

LazyScripter has consistently targeted the airline industry, indicating a strategic focus on sectors with sensitive data and potential operational disruption. They exploit open-source tools to maintain stealth and persistence, employing techniques like obfuscation and web service abuse. Their long-term presence suggests a capability for sustained campaigns aiming to achieve financial gain or espionage objectives.

Key Capabilities

  • Use of njRAT malware
  • KOCTOPUS toolset deployment
  • Spearphishing campaigns
  • Malicious scripts execution
  • Persistence mechanisms

MITRE ATT&CK Tactics

Defense Evasion
Execution
Exfiltration
Lateral Movement
Collection
Discovery
Impact
Reconnaissance
Credential Access

ATT&CK Techniques

T1059.007
T1204.002
T1566.002
T1036
T1583.001
T1588.001
T1102
T1218.005
T1059.001
T1059.003
T1027.010
T1204.001
T1218.011
T1071.004
T1566.001
T1608.001
T1547.001
T1059.005
T1105

Software / Tooling

njRAT
KOCTOPUS

Campaigns & Victims

LazyScripter conducts targeted campaigns against airlines, utilizing njRAT and KOCTOPUS for long-term access. Their activities suggest a focus on data exfiltration and system disruption, with sustained operations potentially across multiple years.

IOC Patterns

  • Web service domains linked to malicious activity
  • Obfuscated JavaScript scripts delivered via spearphishing
  • Fileless malware execution through Mshta or Rundll32
  • Registry changes for persistence

Recommended Actions

  • Monitor web services and domains for suspicious activities
  • Implement network segmentation, especially for critical systems
  • Enhance user training on phishing emails with malicious links/attachments
  • Conduct regular vulnerability assessments focusing on aviation sector risks
  • Use threat intelligence feeds to detect and block known LazyScripter IOC

Suggested Tags

APT
malware
espionage
financial-sector
aviation-industry

Confidence Assessment

High confidence in targeting methods and toolset, while gaps remain in understanding specific campaigns and exact motivations. Additional data on campaign details and long-term objectives would improve the intelligence picture.

ATT&CK Techniques

Execution
6 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. MalwareBytes LazyScripter Feb 2021 — Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

Intel Summary

20

Techniques

2

Tools

0

Campaigns

0

IOCs

0

Observed Data

6

Tactics

Tags

APT
malware
espionage
financial-sector
aviation-industry

Details

MITRE ID
G0140
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--abc5a1d4-f0dc-49d1-88a1-4a80e478bb03
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.