LazyScripter is an advanced persistent threat group active since at least 2018 that primarily targets the airline industry and relies heavily on publicly available tools and open-source remote access Trojans. Its operations include phishing campaigns against European entities. Initial-access lures have impersonated the United Nations World Tourism Organization and the International Air Transport Association, using fake recruitment offers, compressed JavaScript attachments, and PDF documents linking to malicious downloads. Other campaigns have used fake software-patch notices to deliver password-protected archives containing obfuscated batch scripts. LazyScripter uses JavaScript, VBScript, PowerShell, and Windows command scripts for payload delivery and execution. Its toolset includes H-Worm, also known as Houdini, and Koadic; it has abused the Windows HTML Application host to execute Koadic stagers. Persistence mechanisms include registry autorun entries, Startup-folder payloads, and scheduled tasks. Defense-evasion techniques include script obfuscation, disguising executables with security-software icons, disabling Microsoft Defender protections and services, adding antivirus exclusions, and deleting security-related event logs. Associated scripts attempt elevation through Windows scripting and weaken User Account Control settings. PowerShell payloads collect host and user identifiers, operating-system details, Active Directory domain membership, administrative status, and running-process information, encrypting collected data with AES-CBC before transmission to command-and-control infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
31 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
LazyScripter is listed in the detection's annotations.
Referenced only as an annotated actor associated with the detection technique.
Listed as an associated threat actor for the JavaScript-execution technique.
Listed in the detection annotation metadata.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.