Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
20
techniques
7
software
11,347
corpus matches
profile
LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.
techniques
20 attributed · most-instrumented first
Ingress Tool Transfer
command-and-control
Malicious File
execution
PowerShell
execution
Spearphishing Attachment
initial-access
Windows Command Shell
execution
Registry Run Keys / Startup Folder
+8 more techniques
software
7 malware & tools attributed
Koadic
S0250
QuasarRAT
S0262
Remcos
S0332
Empire
S0363
njRAT
S0385
ngrok
S0508
KOCTOPUS
S0669
read this carefully
11,347 corpus matches is not attribution
That count is indicators which exhibit techniques LazyScripter is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
persistence · privilege-escalation
showing 30 of 11,347