LazyScripter is a threat actor-associated malware/tooling entry referenced in the provided content. It has been delivered via spam emails containing a link that redirects the victim to download a malicious document. The content also states that LazyScripter has used mshta.exe to execute Koadic stagers, indicating use of the legitimate Windows HTML Application Host as a living-off-the-land execution mechanism for staging follow-on payloads. High-confidence behaviors directly mentioned in the content are malicious-link email delivery and mshta.exe-based execution of Koadic stagers. No additional victimology, industry targeting, or specific indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses spam emails with redirect links to deliver malicious documents.
Malware delivered by spam emails that redirect victims to download a malicious document.
Uses mshta.exe to execute Koadic stagers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.