LazyScripter

MITRE ATT&CK: G0140 View on attack.mitre.org

Aliases: LazyScripter

First seen
2018-01-01 00:00:00
Primary motivation
espionage
Sophistication
intermediate
Resource level
team
Actor type
criminal
Related IoCs
1 (1 malicious)
Last IoC activity
2026-03-19 03:38:37
Profile updated
2026-07-07 12:30:33

Targeted industries: transportation-and-logistics

Context

LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to LazyScripter (G0140). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 1cf356e4c59a8cce27d5defffcb4eb66140a162d539cbe4864e0b0c0eb9c9079 2026-03-19 1

Detection coverage

  • 23 YARA rules
  • 509 Sigma rules

Malware & tools used

  • Malicious Link (attack-pattern)
  • Mshta (attack-pattern)
  • Upload Malware (attack-pattern)
  • Malicious File (attack-pattern)
  • Web Service (attack-pattern)
  • JavaScript (attack-pattern)
  • Domains (attack-pattern)
  • Visual Basic (attack-pattern)
  • DNS (attack-pattern)
  • Malware (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Masquerading (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • PowerShell (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Rundll32 (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Web Services (attack-pattern)
  • ngrok (malware)
  • Empire (malware)
  • Remcos (malware)
  • Koadic (malware)
  • njRAT (malware)

Reports & references

  • MITRE ATT&CK — G0140 (report)
  • web.archive.org — Lazyscripter (report)

External references