ATT&CKReferencesMalwareBytes LazyScripter Feb 2021

MalwareBytes LazyScripter Feb 2021

Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples52

TechniqueUsed byProcedure example
T1005
Data from Local System
ToolKoadic

Koadic can download files off the target system to send back to the server.

T1016
System Network Configuration Discovery
ToolKoadic

Koadic can retrieve the contents of the IP routing table as well as information about the Windows domain.

T1027.010
Command Obfuscation
GroupLazyScripter

LazyScripter has leveraged the BatchEncryption tool to perform advanced batch script obfuscation and encoding techniques.

T1027.010
Command Obfuscation
MalwareKOCTOPUS

KOCTOPUS has obfuscated scripts with the BatchEncryption tool.

T1033
System Owner/User Discovery
ToolKoadic

Koadic can identify logged in users across the domain and views user sessions.

T1036
Masquerading
GroupLazyScripter

LazyScripter has used several different security software icons to disguise executables.

T1053.005
Scheduled Task
ToolKoadic

Koadic has used scheduled tasks to add persistence.

T1059.001
PowerShell
ToolKoadic

Koadic has used PowerShell to establish persistence.

T1059.001
PowerShell
GroupLazyScripter

LazyScripter has used PowerShell scripts to execute malicious code.

T1059.001
PowerShell
MalwareKOCTOPUS

KOCTOPUS has used PowerShell commands to download additional files.

T1059.003
Windows Command Shell
GroupLazyScripter

LazyScripter has used batch files to deploy open-source and multi-stage RATs.

T1059.003
Windows Command Shell
MalwareKOCTOPUS

KOCTOPUS has used `cmd.exe` and batch files for execution.

T1059.003
Windows Command Shell
ToolKoadic

Koadic can open an interactive command-shell to perform command line functions on victim machines. Koadic performs most of its operations using Windows Script Host (Jscript) and to run arbitrary shellcode.

T1059.005
Visual Basic
GroupLazyScripter

LazyScripter has used VBScript to execute malicious code.

T1059.005
Visual Basic
MalwareKOCTOPUS

KOCTOPUS has used VBScript to call wscript to execute a PowerShell command.

T1059.007
JavaScript
GroupLazyScripter

LazyScripter has used JavaScript in its attacks.

T1070.009
Clear Persistence
MalwareKOCTOPUS

KOCTOPUS can delete created registry keys used for persistence as part of its cleanup procedure.

T1071.001
Web Protocols
ToolKoadic

Koadic has used HTTP for C2 communications.

T1071.004
DNS
GroupLazyScripter

LazyScripter has leveraged dynamic DNS providers for C2 communications.

T1082
System Information Discovery
MalwareKOCTOPUS

KOCTOPUS has checked the OS version using `wmic.exe` and the `find` command.

T1082
System Information Discovery
ToolKoadic

Koadic can obtain the OS version and build, computer name, and processor architecture from a compromised host.

T1083
File and Directory Discovery
ToolKoadic

Koadic can obtain a list of directories.

T1090
Proxy
MalwareKOCTOPUS

KOCTOPUS has deployed a modified version of Invoke-Ngrok to expose open local ports to the Internet.

T1102
Web Service
GroupLazyScripter

LazyScripter has used GitHub to host its payloads to operate spam campaigns.

T1105
Ingress Tool Transfer
GroupLazyScripter

LazyScripter had downloaded additional tools to a compromised host.

T1105
Ingress Tool Transfer
MalwareKOCTOPUS

KOCTOPUS has executed a PowerShell command to download a file to the system.

T1105
Ingress Tool Transfer
ToolKoadic

Koadic can download additional files and tools.

T1106
Native API
MalwareKOCTOPUS

KOCTOPUS can use the `LoadResource` and `CreateProcessW` APIs for execution.

T1112
Modify Registry
MalwareKOCTOPUS

KOCTOPUS has added and deleted keys from the Registry.

T1140
Deobfuscate/Decode Files or Information
MalwareKOCTOPUS

KOCTOPUS has deobfuscated itself before executing its commands.

T1204.001
Malicious Link
GroupLazyScripter

LazyScripter has relied upon users clicking on links to malicious files.

T1204.001
Malicious Link
MalwareKOCTOPUS

KOCTOPUS has relied on victims clicking on a malicious link delivered via email.

T1204.002
Malicious File
MalwareKOCTOPUS

KOCTOPUS has relied on victims clicking a malicious document for execution.

T1204.002
Malicious File
GroupLazyScripter

LazyScripter has lured users to open malicious email attachments.

T1218.005
Mshta
GroupLazyScripter

LazyScripter has used `mshta.exe` to execute Koadic stagers.

T1218.005
Mshta
ToolKoadic

Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence.

T1218.011
Rundll32
GroupLazyScripter

LazyScripter has used `rundll32.exe` to execute Koadic stagers.

T1547.001
Registry Run Keys / Startup Folder
MalwareKOCTOPUS

KOCTOPUS can set the AutoRun Registry key with a PowerShell command.

T1547.001
Registry Run Keys / Startup Folder
ToolKoadic

Koadic has added persistence to the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run` Registry key.

T1547.001
Registry Run Keys / Startup Folder
GroupLazyScripter

LazyScripter has achieved persistence via writing a PowerShell script to the autorun registry key.

T1548.002
Bypass User Account Control
MalwareKOCTOPUS

KOCTOPUS will perform UAC bypass either through fodhelper.exe or eventvwr.exe.

T1564.003
Hidden Window
ToolKoadic

Koadic has used the command Powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden to hide its window.

T1564.003
Hidden Window
MalwareKOCTOPUS

KOCTOPUS has used -WindowsStyle Hidden to hide the command window.

T1566.001
Spearphishing Attachment
GroupLazyScripter

LazyScripter has used spam emails weaponized with archive or document files as its initial infection vector.

T1566.001
Spearphishing Attachment
MalwareKOCTOPUS

KOCTOPUS has been distributed via spearphishing emails with malicious attachments.

T1566.002
Spearphishing Link
GroupLazyScripter

LazyScripter has used spam emails that contain a link that redirects the victim to download a malicious document.

T1566.002
Spearphishing Link
MalwareKOCTOPUS

KOCTOPUS has been distributed as a malicious link within an email.

T1583.001
Domains
GroupLazyScripter

LazyScripter has used dynamic DNS providers to create legitimate-looking subdomains for C2.

T1583.006
Web Services
GroupLazyScripter

LazyScripter has established GitHub accounts to host its toolsets.

T1588.001
Malware
GroupLazyScripter

LazyScripter has used a variety of open-source remote access Trojans for its operations.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.