Researchers linked new LazyScripter activity to the Octopus backdoor after analyzing malicious document lures that targeted Windows users with a fake patch PDF and a Microsoft Word file containing embedded fake PDF objects. In both cases, user interaction triggered heavily obfuscated batch scripts that downloaded additional payloads from hpsj.firewall-gateway.net, a domain tied to the campaign. Reporting indicates the group has targeted the airline sector since at least 2018, and the latest samples reused infrastructure and tradecraft previously associated with Octopus.
The scripts focused on rapid host takeover by elevating privileges, disabling Microsoft Defender and other Windows security controls, tampering with services and scheduled tasks, modifying the registry for persistence, and using PowerShell download cradles to fetch next-stage malware over ports 80 and 443. The final payload collected host, user, and process information, encrypted the stolen data with AES-CBC, and sent it to command-and-control endpoints on the same domain. MITRE ATT&CK tracking for LazyScripter also aligns the group with phishing-led initial access, PowerShell and VBScript execution, registry-based persistence, defense evasion, tunneling, and RAT-style post-compromise activity.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
On May 10, 2022, a GitHub-hosted analysis described a malicious PDF lure attributed to LazyScripter that masqueraded as a patch installer, downloaded a password-protected ZIP, and dropped obfuscated batch scripts. The write-up detailed privilege escalation, Defender tampering, persistence, follow-on PowerShell payload retrieval, and AES-CBC-encrypted data theft to hpsj.firewall-gateway.net endpoints.
On May 9, 2022, SANS published analysis of a malicious Word document that used embedded fake PDF objects to launch an obfuscated batch script instead of VBA macros. The script disabled Microsoft Defender and other protections, established persistence, and downloaded additional payloads from hpsj.firewall-gateway.net infrastructure linked to the Octopus backdoor.
A Malwarebytes PDF report on LazyScripter was published in 2021, indicating public documentation of the group by that time. The reference provides only the year through the file path.
The SANS diary says the Octopus backdoor had been documented previously in 2020 before the newly analyzed sample appeared. This establishes prior public reporting on the malware family.
The analyzed malware write-up states that the LazyScripter threat group has mainly targeted the airline industry since at least 2018. This is the earliest explicit temporal anchor in the references.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceisc.sans.edu
Open sourcemalwarebytes.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.