LaZagne

MITRE ATT&CK: S0349 View on attack.mitre.org

Aliases: LaZagne

First seen
2014-08-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Operating systems
linux, macos, windows
Related IoCs
11 (11 malicious)
Last IoC activity
2026-08-20 10:55:46
Profile updated
2026-07-07 12:49:17

Context

LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system. It has modules for Windows, Linux, and OSX, but is mainly focused on Windows systems. LaZagne is publicly available on GitHub.

Recent IoC activity

11 malicious indicators in Maltiverse are attributed to LaZagne (S0349). The 11 most recently updated:

Detection coverage

  • 1 YARA rules
  • 133 Sigma rules

Malware & tools used

  • Credentials In Files (attack-pattern)
  • Windows Credential Manager (attack-pattern)
  • LSA Secrets (attack-pattern)
  • /etc/passwd and /etc/shadow (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Cached Domain Credentials (attack-pattern)
  • Credentials from Password Stores (attack-pattern)
  • Keychain (attack-pattern)
  • Proc Filesystem (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Hacktool_Lazagne_Strings (yara-rule)

Reports & references

  • Kaspersky — 107610 (report)
  • MITRE ATT&CK — G0100 (report)
  • decoded.avast.io — Apt Group Targeting Governmental Agencies In East Asia (report)
  • Cisco Talos — Uat 5918 Targets Critical Infra In Taiwan (report)
  • Trend Micro — Ransomware Spotlight Ransomexx (report)
  • yoroi.company — Shadows From The Past Threaten Italian Enterprises (report)
  • thedfirreport.com — Seo Poisoning A Gootloader Story (report)
  • marcoramilli.com — C2 Traffic Patterns Personal Notes (report)
  • malpedia.caad.fkie.fraunhofer.de — Py.Lazagne (report)
  • fourcore.io — Threat Hunting Browser Credential Stealing (report)
  • github.com — Lazagne (report)
  • edu.anarcho-copy.org — Group Ib%20Redcurl (report)
  • Mandiant — Alphv Ransomware Backup (report)
  • infinitumit.com.tr — Apt 35 (report)
  • Trend Micro — Weaponizing Open Source Software For Targeted Attacks (report)
  • MITRE ATT&CK — S0349 (report)

External references