s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.lazyscripter

📛 Threat Title

Malware family: Lazyscripter

Category: Lazyscripter First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.lazyscripter`. Printable name: Lazyscripter.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ps1.lazyscripter VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ps1.lazyscripter

IOC database

Type
domain
Value
ps1.lazyscripter
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ps1.lazyscripter

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ps1.lazyscripter

References (1)

Remediations (10)

  • web:attack.mitre.org

    LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets. [1] ID: G0140 Contributors: Manikantan Srinivasan, NEC Corporation India; Pooja Natarajan, NEC Corporation India; Hiroki Nagahama, NEC Corporation Version: 1.1 Created: 24 November 2021 Last Modified: 17 November 2024 Version Permalink Live Version ATT&CK ...

  • web:incidentbuddy.ai

    Threat profile for LazyScripter (Ransomware Gang). 20 MITRE ATT&CK techniques mapped. See affected software and security gaps.

  • web:intel.mjolnirsecurity.com

    LazyScripter (also tracked as None publicly documented) is a threat group attributed to Unknown. The group primarily targets Airlines, IATA members for intelligence collection and operational objectives aligned with state interests.

  • web:lab52.io

    Additionally, after the analysis of the samples, we discovered the usage of a free and popular online obfuscating tool for scripts, which would inject their own downloader for a njRAT sample within LazyScripter's malware .

  • web:openhunting.io

    Opensource Threat Hunting & Intelligence (Malwarebytes) Malwarebytes' Threat Intelligence analysts are continually researching and monitoring active malware campaigns and actor groups as the prevalence and sophistication of targeted attacks rapidly evolves. In this paper, we introduce a new APT group we have named LazyScripter , presenting in-depth analysis of the tactics, techniques ...

  • web:redteam.y-security.de

    LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets. 1

  • web:www.ishareinfo.com

    (Malwarebytes) Malwarebytes Threat Intelligence analysts are continually researching and monitoring active malware campaigns and actor groups as the prevalence and sophistication of targeted attacks rapidly evolves. In this paper, we introduce a new APT group we have named LazyScripter , presenting in-depth analysis of the tactics, techniques, procedures, and infrastructure employed by this ...

  • web:www.securityscientist.net

    LazyScripter (G0140) uses spearphishing, KOCTOPUS, Empire, and Octopus RAT to target immigration applicants. Explore their full MITRE ATT&CK technique mapping and defence strategies.

  • web:www.securityweek.com

    Cybercrime New 'LazyScripter' Hacking Group Targets Airlines A recently identified threat actor that remained unnoticed for roughly two years appears focused on the targeting of airlines that are using the BSPLink financial settlement software made by the International Air Transport Association (IATA), cybersecurity firm Malwarebytes reported on Wednesday.

  • web:www.wokb.cz

    Executive Summary Malwarebytes' Threat Intelligence analysts are continually researching and monitoring active malware campaigns and actor groups as the prevalence and sophistication of targeted attacks rapidly evolves. In this paper, we introduce a new APT group we have named LazyScripter , presenting in-depth analysis of the tactics, techniques, procedures, and infrastructure employed by ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.