LaZagne is an open-source password recovery and credential extraction tool designed to retrieve secrets stored locally on compromised systems. It is widely used as a dual-use post-exploitation utility by both legitimate testers and malicious actors to harvest credentials from operating system stores and common applications. Supported targets include web browsers, mail clients, chat applications, database tools, Wi-Fi profiles, file transfer and remote administration tools, SSH- and VPN-related material, Windows credential stores, DPAPI-related data, LSA secrets, Vault data, keychains, keyrings, and password hashes across multiple platforms.
LaZagne is primarily associated with credential theft after initial compromise. It has been observed in intrusions conducted by a broad range of threat actors, including ransomware operators and espionage groups such as Akira, Ransom Cartel, Evilnum, APT15, APT33, MuddyWater, OilRig, Leafminer, RedCurl, and others. In these operations it is commonly paired with tools such as Mimikatz and used to support privilege escalation, lateral movement, and broader post-exploitation objectives by extracting passwords from browsers, databases, email clients, and locally stored credential repositories.
The tool runs on Windows and Linux, and project documentation also describes macOS support with limitations tied to user password access. Some credential sources require elevated privileges, particularly on Windows for Wi-Fi credentials and certain protected secrets. LaZagne can be executed selectively against specific module categories or across all supported modules, and it can export recovered data in text or JSON formats. Its code has also been integrated into the Pupy framework, enabling in-memory execution without writing the Python source to disk, which can reduce forensic visibility.
LaZagne is not a self-propagating malware family but a credential-harvesting utility frequently embedded into larger intrusion chains. Threat actors have delivered or invoked custom versions of LaZagne from remote payload frameworks, including Python-based RAT ecosystems, to dump passwords and sometimes collect cookie data for exfiltration to command-and-control infrastructure. Its prevalence in real-world intrusions and broad application coverage make it a common component of credential access tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During the analysis of PyVil RAT, on several occasions, the malware received from the C2 a new Python module to execute. This Python module is a custom version of the LaZagne Project which the Evilnum group has used in the past. The script will try to dump passwords and collect cookie information to send to the C2.
Inception has obtained and used open-source tools such as LaZagne.
Inception has obtained and used open-source tools such as LaZagne.
LaZagne can obtain credentials from chats, databases, mail, and WiFi.
LaZagne can obtain credentials from chats, databases, mail, and WiFi.
For example, APT15 uses widely accessible tools like Mimikatz and LaZagne... APT15 used the Mimikatz and LaZagne tools
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Akira operators aggressively pursue credential access using Mimikatz and the DonPAPI toolkit to harvest passwords from Windows credentials, cached browser passwords, RDP/VNC logins, LSASS memory dumps, SAM database extraction, and NTDS.dit copying from domain controllers.
Дамп LSASS (T1003.001) через Mimikatz или LaZagne, эксплуатация уязвимостей Active Directory, Kerberoasting.
T1003.005 MuddyWater has performed credential dumping with LaZagne.
The script will try to dump passwords and collect cookie information to send to the C2.
Each software stores its passwords using different techniques (plaintext, APIs, custom algorithms, databases, etc.).
Environnement variable FileZilla gFTP History files Shares SSH private keys KeePass Configuration Files
PyVil RAT possesses different functionalities, and enables the attackers to... deploy more tools such as LaZagne in order to steal credentials.
Unit 42 observed a Ransom Cartel threat actor using a tool called DonPAPI... DonPAPI is used to search machines for certain files known to be DPAPI blobs, including Wi-Fi keys, RDP passwords, credentials saved in web browsers... To compromise Linux ESXi devices, Ransom Cartel uses DonPAPI to harvest credentials stored in web browsers used to authenticate to the vCenter web interface.
PyVil RAT possesses different functionalities, and enables the attackers to exfiltrate data, perform keylogging and the taking of screenshots, and the deployment of more tools such as LaZagne... During the analysis of PyVil RAT, on several occasions, the malware received from the C2 a new Python module to execute.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
60 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential theft tool used to dump credentials during post-compromise activity.
Credential dumping tool used to harvest credentials during the attack chain before the encryptor was deployed.
Credential recovery tool used to dump passwords from browsers, databases, email clients, and memory as part of Beast ransomware operations.
Credential extraction tool used in Akira intrusions to harvest stored credentials as part of pre-ransomware operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.