LaZagne is an open-source credential recovery and password harvesting tool widely abused by threat actors during post-compromise operations. It is designed to extract locally stored secrets from a broad range of software and system sources, including web browsers, chat clients, databases, mail applications, Wi-Fi profiles, Windows credential stores, and in some cases credentials exposed through files or the Windows Registry. On Windows systems it has been used to recover passwords from browsers such as Chrome, Internet Explorer, and Firefox, and it is frequently paired with other offensive tooling to expand access after an initial foothold.
The tool is commonly used for credential theft rather than initial intrusion. Multiple intrusion sets and ransomware operators have incorporated LaZagne into hands-on-keyboard activity, including APT33, OilRig, RedCurl, Leafminer, Evilnum, STIBNITE, Earth Akhlut, Dharma affiliates, Nefilim operators, and intruders associated with TrickBot-enabled compromises. It has also appeared inside custom malware ecosystems and repackaged variants, including Python-based adaptations and modified forks embedded in loaders or remote access malware. Examples include custom versions used by Evilnum and Qealler, as well as deployment by PyXie Lite and NexusLogger to extend credential collection.
LaZagne’s operational role is typically credential access and follow-on enablement. Attackers use it to harvest passwords from the local machine, then leverage the recovered credentials for privilege escalation, lateral movement, persistence expansion, access to email or browser-stored accounts, and broader post-exploitation objectives. In ransomware intrusions, LaZagne has been used alongside tools such as Mimikatz, AdFind, BloodHound, PsExec, and remote administration utilities to support network traversal and pre-encryption staging. In espionage activity, it has supported collection of account credentials and browser data for sustained access and intelligence gathering.
LaZagne is most strongly associated with Windows in the supplied facts, though it exists as a Python-based project and has been embedded into varied malware chains. Its dual-use nature as a legitimate offensive security utility and an attacker-favored credential theft tool makes it common in both red-team contexts and real-world intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox.
LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox.
LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox.
LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox.
During the analysis of PyVil RAT, on several occasions, the malware received from the C2 a new Python module to execute. This Python module is a custom version of the LaZagne Project which the Evilnum group has used in the past.
LaZagne is an open-source tool for retrieving passwords stored on a local computer. The original Python code is compiled into an executable.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DPAPI.
OS Credential Dumping: LSASS Memory T1003.001 Basic description The subtechnique known as OS Credential Dumping: LSASS Memory T1003.001 is used by attackers to obtain credentials in a Windows OS.
The main goal of the group is to spy on its infected targets and steal information such as passwords, documents, browser cookies, email credentials and more.
APT3 has a tool that can locate credentials in files on the file system such as those from Firefox or Chrome.
Adversaries may search the Registry on compromised systems for insecurely stored credentials... Example commands to find Registry keys related to password information: Local Machine Hive: reg query HKLM /f password /t REG_SZ /s Current User Hive: reg query HKCU /f password /t REG_SZ /s
Collects cookies... Collects KeePass safes... _get_passwords All Collects passwords with Lazagne | Collects cookies Collects LogMeIn data Collects Citrix data Collects KeePass safes
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
86 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential recovery tool used to parse application configurations and recover stored credentials from a compromised host.
Credential theft tool used to dump credentials during post-compromise activity.
Credential-dumping tool listed as part of protections against Elfin activity.
Credential dumping tool used to harvest credentials during the attack chain before the encryptor was deployed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.