This cybercrime group uses the most basic tactics around — but they seem to be working just fine
Hacking techniques don’t have to be particularly advanced to be successful. Case in point – Lazy Koala.
Cybersecurity researchers from Positive Technologies Expert Security Center (PT ESC) recently uncovered a new threat actor, which they dubbed Lazy Koala. Nothing about this group is notably progressive or sophisticated, but it is achieving outstanding results.
As per the report, the attackers are targeting enterprises in Russia and six Commonwealth of Independent States countries – Belarus, Kazakhstan, Uzbekistan, Kyrgyzstan, Tajikistan, and Armenia. Their victims work in government agencies, financial organizations, and educational institutions, and they mostly go for login credentials to various services.
Exfiltration via Telegram
So far, almost 900 accounts have been compromised, the researchers said. It is unclear what the attackers are doing with the information, but it’s likely that they’re either selling it on the dark web, or using it in further, more devastating attacks.
The attacks are simple – they include crafting convincing phishing attacks, often in languages native to the locals, and getting the victims to download and run the attachment. The files being distributed in these phishing attacks deploy a “primitive password stealer malware”.
The infostealer then grabs the files and exfiltrates them via telegram bots. The person handling these bots is called Koala, giving PT ESC the idea behind the name.
“The calling card of the new group is this: ‘harder doesn’t mean better.’ Lazy Koala doesn’t bother with complex tools, tactics, and techniques, but they still get the job done,” said Denis Kuvshinov, Head of Threat Analysis, Positive Technologies Expert Security Center.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“After establishing itself on the infected device, the malware exfiltrates the stolen data using Telegram, a favorite tool among attackers,” Kuvshinov added.
PT ESC said that it notified the victims, adding that the information stolen in this campaign will most likely be sold on the dark web.
More from TechRadar Pro
Hacking techniques don’t have to be particularly advanced to be successful. Case in point – Lazy Koala. Cybersecurity researchers from Positive Technologies Expert Security Center (PT ESC) recently uncovered a new threat actor, which they dubbed Lazy Koala. Nothing about this group is notably progressive or sophisticated, but it is…
Recent Posts
- Amazon’s Adaptive Display for Fire TVs is officially rolling out today
- Here are the 30,000 songs Sony is suing Udio’s AI music generator over
- The FCC is planning to retroactively ban disguised DJI gadgets
- The Odyssey turned me into an IMAX believer
- IKEA just dropped its Halloween collection in the middle of summer — and these ghostly lights are so cute, I can’t wait until October
Archives
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023