LaZagne is an open-source credential-recovery and password-harvesting tool, implemented primarily in Python and commonly abused after compromise to collect credentials stored locally on Windows systems. It can recover credentials from web browsers, chat applications, databases, email software, Wi-Fi configurations, Windows Credential Manager, and other commonly used applications, including by accessing DPAPI-protected material. It has been used by multiple threat actors and criminal operations, including OilRig, RedCurl, Nefilim operators, Evilnum, STIBNITE, and Earth Akhlut, typically alongside other credential-access and post-exploitation tools. Custom or bundled variants of LaZagne have also been incorporated into malware such as Qealler and PyVil RAT to automate credential theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Дамп LSASS ... через Mimikatz или LaZagne
15 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox.
LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox.
LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox.
LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox.
During the analysis of PyVil RAT, on several occasions, the malware received from the C2 a new Python module to execute. This Python module is a custom version of the LaZagne Project which the Evilnum group has used in the past.
LaZagne is an open-source tool for retrieving passwords stored on a local computer. The original Python code is compiled into an executable.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DPAPI.
OS Credential Dumping: LSASS Memory T1003.001 Basic description The subtechnique known as OS Credential Dumping: LSASS Memory T1003.001 is used by attackers to obtain credentials in a Windows OS.
The main goal of the group is to spy on its infected targets and steal information such as passwords, documents, browser cookies, email credentials and more.
T1552.001 Credential in Files ... This EQL query uses the process.entity_id field to detect a process accessing multiple sensitive files in a short period of time.
Adversaries may search the Registry on compromised systems for insecurely stored credentials... Example commands to find Registry keys related to password information: Local Machine Hive: reg query HKLM /f password /t REG_SZ /s Current User Hive: reg query HKCU /f password /t REG_SZ /s
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
87 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential recovery tool used to parse application configurations and recover stored credentials from a compromised host.
Credential theft tool used to dump credentials during post-compromise activity.
Credential-dumping tool listed as part of protections against Elfin activity.
Credential dumping tool used to harvest credentials during the attack chain before the encryptor was deployed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.