lslsass is a credential-dumping malware/tool that dumps active logon session password hashes from the Windows lsass process. The provided content directly states that its capability is to dump active logon session password hashes from LSASS. No additional high-confidence details about infection vector, associated threat actor, targeted industries, or specific indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
「192.168.1.x-PWHashes.txt」というファイルが一時的に作成された痕跡があったとします…この特徴的な「PWHashes.txt」という文字列で…PWDumpXを実行した際に作成されるファイルであることが分かります。…サーバー上のパスワードハッシュを入手する攻撃が実行されたと推測される
Examples include: “dumped the LSASS process memory using the MiniDump function,” “injecting itself into lsass.exe,” “used ProcDump to dump the LSASS process memory,” “retrieve credentials from LSASS memory,” and “attempted to access hashed credentials from the LSASS process memory space.”
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential dumping tool focused on extracting password hashes from active logon sessions in LSASS.
Tool focused on extracting active logon session password hashes from LSASS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.