LazyScripter
MITRE ATT&CK: G0140 View on attack.mitre.org
Aliases: LazyScripter
- First seen
- 2018-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- criminal
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-03-19 03:38:37
- Profile updated
- 2026-07-07 12:30:33
Targeted industries: transportation-and-logistics
Context
LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to LazyScripter (G0140). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 1cf356e4c59a8cce27d5defffcb4eb66140a162d539cbe4864e0b0c0eb9c9079 | 2026-03-19 | 1 |
Detection coverage
- 23 YARA rules
- 509 Sigma rules
Malware & tools used
- Malicious Link (attack-pattern)
- Mshta (attack-pattern)
- Upload Malware (attack-pattern)
- Malicious File (attack-pattern)
- Web Service (attack-pattern)
- JavaScript (attack-pattern)
- Domains (attack-pattern)
- Visual Basic (attack-pattern)
- DNS (attack-pattern)
- Malware (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Masquerading (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- PowerShell (attack-pattern)
- Windows Command Shell (attack-pattern)
- Command Obfuscation (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Rundll32 (attack-pattern)
- Spearphishing Link (attack-pattern)
- Web Services (attack-pattern)
- ngrok (malware)
- Empire (malware)
- Remcos (malware)
- Koadic (malware)
- njRAT (malware)
Reports & references
- MITRE ATT&CK — G0140 (report)
- web.archive.org — Lazyscripter (report)