LazyScripter

APT / StateG0140 ↗
Techniques (MITRE ATT&CK)20
SourceMITRE ATT&CK

About the group

LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity25
Impact: High
T1566.001T1059.001ENTRYInitial accessSpearphishingAttachmentEXECExecutionPowerShellPERSPersistenceRegistry Run Keys/ Startup Folder

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 20

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 1906

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port45.128.234.124:443Remcosthreatfox
ip:port198.135.49.110:4489Remcosthreatfox
ip:port37.120.206.165:60507Remcosthreatfox
ip:port103.83.87.86:2404Remcosthreatfox
ip:port185.149.24.115:2404Remcosthreatfox
ip:port128.90.108.225:2424Remcosthreatfox
ip:port103.83.86.40:14642Remcosthreatfox
ip:port31.59.137.81:4565Remcosthreatfox
domainjustily.duckdns.orgRemcosthreatfox
ip:port192.162.199.218:2222Quasar RATthreatfox
ip:port128.90.108.89:2424Remcosthreatfox
ip:port103.254.61.170:3889Remcosthreatfox
ip:port46.246.14.21:5987Remcosthreatfox
ip:port194.116.236.83:15800Remcosthreatfox
md5_hash1cf8cce965f8f2089ce67ef811b29d13NjRATthreatfox
sha256_hashd7fea5f6217db6e04f75333a65a46cdfcc523c7f3ddc29cfaecb18cd8876ea98NjRATthreatfox
sha1_hashca868ac1e4f42282fb74865fc2f9edf38b052e4bNjRATthreatfox
sha256_hashd5c4983535d57d69fc6f8c09ff4a3838d6a61ac6b149de67b89c0c062968d9cdNjRATthreatfox
md5_hash1742ad51f743c9e518abec7fc6f9451bNjRATthreatfox
sha1_hash19dc42491a499830d7638933b5f457740ffce395NjRATthreatfox
ip:port204.44.93.119:7878Remcosthreatfox
ip:port114.66.20.236:8008Quasar RATthreatfox
ip:port128.90.108.50:2424Remcosthreatfox
ip:port128.90.102.194:2015Remcosthreatfox
ip:port43.228.157.72:1208Remcosthreatfox
ip:port102.220.163.130:14644Remcosthreatfox
ip:port128.90.108.109:2405Remcosthreatfox
ip:port84.32.41.212:443Remcosthreatfox
ip:port194.116.236.83:2404Remcosthreatfox
ip:port194.116.236.83:15700Remcosthreatfox

+1906 indicators in total. See them all on the IOCs page.

LazyScripter uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →