S0669Windows

S0669KOCTOPUS

Platforms
1
ATT&CK
14.1
References
2

Description

[KOCTOPUS](https://attack.mitre.org/software/S0669)'s batch variant is loader used by [LazyScripter](https://attack.mitre.org/groups/G0140) since 2018 to launch [Octopus](https://attack.mitre.org/software/S0340) and [Koadic](https://attack.mitre.org/software/S0250) and, in some cases, [QuasarRAT](https://attack.mitre.org/software/S0262). [KOCTOPUS](https://attack.mitre.org/software/S0669) also has a VBA variant that has the same functionality as the batch version.(Citation: MalwareBytes LazyScripter Feb 2021)

Platforms· 1

Windows

Attributed to1

TypeTargetConfidenceTier
GroupLazyScripterg014095%live

References

  1. https://attack.mitre.org/software/S0669
  2. https://www.malwarebytes.com/resources/files/2021/02/lazyscripter.pdf

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
BLACKCOFFEE
Software
DRATzarus
Software
Koadic
Software
ObliqueRAT
Software
Kobalos
Software
Neoichor
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.