LazyScripter is an emerging threat group active since at least 2018 that has primarily targeted the airline industry and has also conducted phishing campaigns against important European entities. The group is associated with socially engineered delivery through malicious email attachments and archive files, often using lures themed around aviation, travel, patching, or employment opportunities while impersonating well-known international organizations. LazyScripter relies heavily on open-source and commodity tooling rather than exclusively bespoke malware. Reported tradecraft includes obtaining and deploying open-source remote access Trojans, hosting tooling on GitHub, and using multi-stage infection chains built with JavaScript, VBScript, batch scripts, PowerShell, and mshta.exe. Observed execution methods include malicious JavaScript droppers, VBScript payloads, PowerShell downloaders, and Koadic stagers launched through mshta.exe. The group has demonstrated persistence through Windows autorun mechanisms, including PowerShell-based registry autoruns and Startup-folder artifacts. In analyzed campaigns, LazyScripter-associated payload chains also used scheduled execution and registry-based startup to maintain access. Additional observed behavior includes extensive defense evasion through obfuscation and, in at least one analyzed intrusion chain, disabling or degrading Microsoft Defender and other Windows security controls before retrieving follow-on PowerShell payloads. LazyScripter operations have included information theft and remote access. Documented payload behavior includes collection of host and user information, process data, operating system details, administrative context, and network-related system information, followed by encrypted transmission to command-and-control infrastructure. Malware associated with LazyScripter activity has included commodity RAT families such as H-Worm, also known as Houdini, alongside other open-source remote access tooling. Known aliases are limited, and LazyScripter is primarily tracked under the name LazyScripter.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
31 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Listed as an example threat actor associated with the detection's ATT&CK annotations for Linux system binary backdooring/masquerading behavior.
Mentioned only as one of many threat actors associated with the Masquerading technique annotation in a Splunk detection entry; no campaign-specific activity is described in this reference.
Listed as an associated threat actor in detection annotations for Ghostscript exploitation; no specific campaign activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.