G0140: LazyScripter
LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.[1]
Security context for executives and security teams
G0140: LazyScripter describes [LazyScripter](https://attack.mitre.org/groups/G0140) is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.(Citation: MalwareBytes LazyScripter Feb 2021)
Executive priority
G0140: LazyScripter is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G0140: LazyScripter by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G0140: LazyScripter appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
LazyScripter
LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.[1]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1204.001 | Malicious LinkSub-technique | LazyScripter has relied upon users clicking on links to malicious files.[1] |
| Enterprise | T1218.005 | MshtaSub-technique | LazyScripter has used `mshta.exe` to execute Koadic stagers.[1] |
| Enterprise | T1608.001 | Upload MalwareSub-technique | LazyScripter has hosted open-source remote access Trojans used in its operations in GitHub.[1] |
| Enterprise | T1204.002 | Malicious FileSub-technique | LazyScripter has lured users to open malicious email attachments.[1] |
| Enterprise | T1102 | Web Service | LazyScripter has used GitHub to host its payloads to operate spam campaigns.[1] |
| Enterprise | T1059.007 | JavaScriptSub-technique | LazyScripter has used JavaScript in its attacks.[1] |
| Enterprise | T1583.001 | DomainsSub-technique | LazyScripter has used dynamic DNS providers to create legitimate-looking subdomains for C2.[1] |
| Enterprise | T1059.005 | Visual BasicSub-technique | LazyScripter has used VBScript to execute malicious code.[1] |
| Enterprise | T1071.004 | DNSSub-technique | LazyScripter has leveraged dynamic DNS providers for C2 communications.[1] |
| Enterprise | T1588.001 | MalwareSub-technique | LazyScripter has used a variety of open-source remote access Trojans for its operations.[1] |
| Enterprise | T1105 | Ingress Tool Transfer | LazyScripter had downloaded additional tools to a compromised host.[1] |
| Enterprise | T1036 | Masquerading | LazyScripter has used several different security software icons to disguise executables.[1] |
| Enterprise | T1566.001 | Spearphishing AttachmentSub-technique | LazyScripter has used spam emails weaponized with archive or document files as its initial infection vector.[1] |
| Enterprise | T1059.001 | PowerShellSub-technique | LazyScripter has used PowerShell scripts to execute malicious code.[1] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | LazyScripter has used batch files to deploy open-source and multi-stage RATs.[1] |
| Enterprise | T1027.010 | Command ObfuscationSub-technique | LazyScripter has leveraged the BatchEncryption tool to perform advanced batch script obfuscation and encoding techniques.[1] |
| Enterprise | T1547.001 | Registry Run Keys / Startup FolderSub-technique | LazyScripter has achieved persistence via writing a PowerShell script to the autorun registry key.[1] |
| Enterprise | T1218.011 | Rundll32Sub-technique | LazyScripter has used `rundll32.exe` to execute Koadic stagers.[1] |
| Enterprise | T1566.002 | Spearphishing LinkSub-technique | LazyScripter has used spam emails that contain a link that redirects the victim to download a malicious document.[1] |
| Enterprise | T1583.006 | Web ServicesSub-technique | LazyScripter has established GitHub accounts to host its toolsets.[1] |
Groups, software, and campaigns
S0332: Remcos
S0262: QuasarRAT
S0385: njRAT
S0508: ngrok
S0363: Empire
Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.[1][2][3]
S0250: Koadic
S0669: KOCTOPUS
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.1 | Current bundle | 185a578f1021… | ||
| 19.1 | 1.1 | Older bundle | 1c01e90978e2… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]MalwareBytes LazyScripter Feb 2021
Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.
Open source URL - [2]LazyScripter
(Citation: MalwareBytes LazyScripter Feb 2021)
- [3]mitre-attackG0140Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
