Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
ToolKoadic | Koadic can download files off the target system to send back to the server. |
| T1016 System Network Configuration Discovery |
ToolKoadic | Koadic can retrieve the contents of the IP routing table as well as information about the Windows domain. |
| T1027.010 Command Obfuscation |
GroupLazyScripter | LazyScripter has leveraged the BatchEncryption tool to perform advanced batch script obfuscation and encoding techniques. |
| T1027.010 Command Obfuscation |
MalwareKOCTOPUS | KOCTOPUS has obfuscated scripts with the BatchEncryption tool. |
| T1033 System Owner/User Discovery |
ToolKoadic | Koadic can identify logged in users across the domain and views user sessions. |
| T1036 Masquerading |
GroupLazyScripter | LazyScripter has used several different security software icons to disguise executables. |
| T1053.005 Scheduled Task |
ToolKoadic | Koadic has used scheduled tasks to add persistence. |
| T1059.001 PowerShell |
ToolKoadic | Koadic has used PowerShell to establish persistence. |
| T1059.001 PowerShell |
GroupLazyScripter | LazyScripter has used PowerShell scripts to execute malicious code. |
| T1059.001 PowerShell |
MalwareKOCTOPUS | KOCTOPUS has used PowerShell commands to download additional files. |
| T1059.003 Windows Command Shell |
GroupLazyScripter | LazyScripter has used batch files to deploy open-source and multi-stage RATs. |
| T1059.003 Windows Command Shell |
MalwareKOCTOPUS | KOCTOPUS has used `cmd.exe` and batch files for execution. |
| T1059.003 Windows Command Shell |
ToolKoadic | Koadic can open an interactive command-shell to perform command line functions on victim machines. Koadic performs most of its operations using Windows Script Host (Jscript) and to run arbitrary shellcode. |
| T1059.005 Visual Basic |
GroupLazyScripter | LazyScripter has used VBScript to execute malicious code. |
| T1059.005 Visual Basic |
MalwareKOCTOPUS | KOCTOPUS has used VBScript to call wscript to execute a PowerShell command. |
| T1059.007 JavaScript |
GroupLazyScripter | LazyScripter has used JavaScript in its attacks. |
| T1070.009 Clear Persistence |
MalwareKOCTOPUS | KOCTOPUS can delete created registry keys used for persistence as part of its cleanup procedure. |
| T1071.001 Web Protocols |
ToolKoadic | Koadic has used HTTP for C2 communications. |
| T1071.004 DNS |
GroupLazyScripter | LazyScripter has leveraged dynamic DNS providers for C2 communications. |
| T1082 System Information Discovery |
MalwareKOCTOPUS | KOCTOPUS has checked the OS version using `wmic.exe` and the `find` command. |
| T1082 System Information Discovery |
ToolKoadic | Koadic can obtain the OS version and build, computer name, and processor architecture from a compromised host. |
| T1083 File and Directory Discovery |
ToolKoadic | Koadic can obtain a list of directories. |
| T1090 Proxy |
MalwareKOCTOPUS | KOCTOPUS has deployed a modified version of Invoke-Ngrok to expose open local ports to the Internet. |
| T1102 Web Service |
GroupLazyScripter | LazyScripter has used GitHub to host its payloads to operate spam campaigns. |
| T1105 Ingress Tool Transfer |
GroupLazyScripter | LazyScripter had downloaded additional tools to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareKOCTOPUS | KOCTOPUS has executed a PowerShell command to download a file to the system. |
| T1105 Ingress Tool Transfer |
ToolKoadic | Koadic can download additional files and tools. |
| T1106 Native API |
MalwareKOCTOPUS | KOCTOPUS can use the `LoadResource` and `CreateProcessW` APIs for execution. |
| T1112 Modify Registry |
MalwareKOCTOPUS | KOCTOPUS has added and deleted keys from the Registry. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKOCTOPUS | KOCTOPUS has deobfuscated itself before executing its commands. |
| T1204.001 Malicious Link |
GroupLazyScripter | LazyScripter has relied upon users clicking on links to malicious files. |
| T1204.001 Malicious Link |
MalwareKOCTOPUS | KOCTOPUS has relied on victims clicking on a malicious link delivered via email. |
| T1204.002 Malicious File |
MalwareKOCTOPUS | KOCTOPUS has relied on victims clicking a malicious document for execution. |
| T1204.002 Malicious File |
GroupLazyScripter | LazyScripter has lured users to open malicious email attachments. |
| T1218.005 Mshta |
GroupLazyScripter | LazyScripter has used `mshta.exe` to execute Koadic stagers. |
| T1218.005 Mshta |
ToolKoadic | Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence. |
| T1218.011 Rundll32 |
GroupLazyScripter | LazyScripter has used `rundll32.exe` to execute Koadic stagers. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareKOCTOPUS | KOCTOPUS can set the AutoRun Registry key with a PowerShell command. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolKoadic | Koadic has added persistence to the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run` Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLazyScripter | LazyScripter has achieved persistence via writing a PowerShell script to the autorun registry key. |
| T1548.002 Bypass User Account Control |
MalwareKOCTOPUS | KOCTOPUS will perform UAC bypass either through fodhelper.exe or eventvwr.exe. |
| T1564.003 Hidden Window |
ToolKoadic | Koadic has used the command |
| T1564.003 Hidden Window |
MalwareKOCTOPUS | KOCTOPUS has used |
| T1566.001 Spearphishing Attachment |
GroupLazyScripter | LazyScripter has used spam emails weaponized with archive or document files as its initial infection vector. |
| T1566.001 Spearphishing Attachment |
MalwareKOCTOPUS | KOCTOPUS has been distributed via spearphishing emails with malicious attachments. |
| T1566.002 Spearphishing Link |
GroupLazyScripter | LazyScripter has used spam emails that contain a link that redirects the victim to download a malicious document. |
| T1566.002 Spearphishing Link |
MalwareKOCTOPUS | KOCTOPUS has been distributed as a malicious link within an email. |
| T1583.001 Domains |
GroupLazyScripter | LazyScripter has used dynamic DNS providers to create legitimate-looking subdomains for C2. |
| T1583.006 Web Services |
GroupLazyScripter | LazyScripter has established GitHub accounts to host its toolsets. |
| T1588.001 Malware |
GroupLazyScripter | LazyScripter has used a variety of open-source remote access Trojans for its operations. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.