LaZagne is a publicly available, open-source password-recovery and credential-dumping utility used for both legitimate security purposes and malicious credential theft. It retrieves account names and passwords from locally stored application data, including web browsers, email clients, databases, and Wi-Fi configurations, and can recover credentials from memory. On Windows, its credential-access behavior includes LSASS memory dumping and access to DPAPI master keys used to decrypt protected resources. It supports credential collection across multiple platforms and has been deployed in Windows intrusions and Linux-based cloud and container campaigns.
Attackers generally deploy LaZagne after obtaining access to a system to harvest credentials for further access to victim systems and networks. Its use has been documented among espionage actors including APT15, APT33, Inception, Leafminer, MuddyWater, OilRig, and Budworm; ransomware operators and affiliates associated with Akira, LockBit, Ransom Cartel, and Storm-2570; and TeamTNT during its Chimaera campaign. LaZagne is a credential-access tool rather than a ransomware payload or remote-access implant, and its use is not specific to a single threat actor or industry.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
LaZagne can perform credential dumping from memory to obtain account and password information.
LaZagne can obtain credentials from databases, mail, and WiFi across multiple platforms.
LaZagne can obtain credentials from databases, mail, and WiFi across multiple platforms.
LaZagne can obtain credentials from databases, mail, and WiFi across multiple platforms.
They also started employing LaZagne, another open-source application, to enhance their credential-stealing capabilities.
Inception has obtained and used open-source tools such as LaZagne.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Akira threat actors use tools like Mimikatz and LaZagne to dump credentials.
APT15 uses widely accessible tools like Mimikatz and LaZagne (T1003.001, T1003.004, T1003.005).
The actor then tried to dump User Account credentials via SAM database.
APT15 uses widely accessible tools like Mimikatz and LaZagne (T1003.001, T1003.004, T1003.005).
APT15 uses widely accessible tools like Mimikatz and LaZagne (T1003.001, T1003.004, T1003.005).
The main goal of the group is to spy on its infected targets and steal information such as passwords, documents, browser cookies, email credentials and more.
T1552.001 Credential in Files ... This EQL query uses the process.entity_id field to detect a process accessing multiple sensitive files in a short period of time.
Adversaries may search the Registry on compromised systems for insecurely stored credentials... Example commands to find Registry keys related to password information: Local Machine Hive: reg query HKLM /f password /t REG_SZ /s Current User Hive: reg query HKCU /f password /t REG_SZ /s
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
106 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-theft tool identified as part of the Akira intrusion toolkit. The article does not provide tool-specific execution details.
Credential-recovery tool explicitly described as used for credential dumping by Akira operators, contributing to credential exposure that must be addressed during incident recovery.
Credential-recovery tooling used by Storm-2570 to obtain credentials during its post-compromise operations.
Credential-harvesting tool used by Storm-2570 during ransomware intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.