LaZagne is an open-source credential recovery tool used to extract passwords and other locally stored secrets from compromised systems. It is designed to retrieve credentials from a wide range of applications and operating system stores, including web browsers, mail clients, chat applications, database tools, Wi-Fi profiles, file transfer and remote administration tools, SSH-related material, and native credential repositories such as DPAPI, Credential Manager, LSA secrets, Vault files, keyrings, and password hashes. It supports Windows, Linux, and macOS, and can export recovered data in structured formats such as JSON.
In intrusion operations, LaZagne is commonly used as a post-compromise credential-theft utility rather than as a self-propagating payload. It has been observed in campaigns by multiple threat actors, including APT33, APT15, MuddyWater, OilRig, Evilnum, and ransomware operators such as Akira and Beast. Adversaries use it to harvest credentials from browsers, email clients, databases, and other local stores to enable privilege escalation, lateral movement, persistence, and broader access to enterprise resources. Some operators have deployed modified or embedded versions, including Python-based variants delivered as modules by remote access malware.
LaZagne is also integrated into offensive frameworks such as Pupy, allowing in-memory execution without writing the tool to disk, which improves defense evasion. It has been used alongside other credential-access tools such as Mimikatz and browser password dumpers, and in some cases has been executed after rebooting Windows systems into Safe Mode to reduce interference from endpoint protections. Because it is publicly available, extensible, and effective across multiple credential sources and platforms, LaZagne remains a widely used dual-use tool in espionage, financially motivated intrusions, and ransomware attack chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During the analysis of PyVil RAT, on several occasions, the malware received from the C2 a new Python module to execute. This Python module is a custom version of the LaZagne Project which the Evilnum group has used in the past. The script will try to dump passwords and collect cookie information to send to the C2.
Inception has obtained and used open-source tools such as LaZagne.
Inception has obtained and used open-source tools such as LaZagne.
LaZagne can obtain credentials from chats, databases, mail, and WiFi.
LaZagne can obtain credentials from chats, databases, mail, and WiFi.
For example, APT15 uses widely accessible tools like Mimikatz and LaZagne... APT15 used the Mimikatz and LaZagne tools
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Akira operators aggressively pursue credential access using Mimikatz and the DonPAPI toolkit to harvest passwords from Windows credentials, cached browser passwords, RDP/VNC logins, LSASS memory dumps, SAM database extraction, and NTDS.dit copying from domain controllers.
Дамп LSASS (T1003.001) через Mimikatz или LaZagne, эксплуатация уязвимостей Active Directory, Kerberoasting.
T1003.005 MuddyWater has performed credential dumping with LaZagne.
The script will try to dump passwords and collect cookie information to send to the C2.
Each software stores its passwords using different techniques (plaintext, APIs, custom algorithms, databases, etc.).
Environnement variable FileZilla gFTP History files Shares SSH private keys KeePass Configuration Files
PyVil RAT possesses different functionalities, and enables the attackers to... deploy more tools such as LaZagne in order to steal credentials.
The script will try to dump passwords and collect cookie information to send to the C2.
PyVil RAT possesses different functionalities, and enables the attackers to exfiltrate data, perform keylogging and the taking of screenshots, and the deployment of more tools such as LaZagne... During the analysis of PyVil RAT, on several occasions, the malware received from the C2 a new Python module to execute.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
59 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential theft tool used to dump credentials during post-compromise activity.
Credential dumping tool used to harvest credentials during the attack chain before the encryptor was deployed.
Credential recovery tool used to dump passwords from browsers, databases, email clients, and memory as part of Beast ransomware operations.
Credential extraction tool used in Akira intrusions to harvest stored credentials as part of pre-ransomware operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.