LaZagne
MITRE ATT&CK: S0349 View on attack.mitre.org
Aliases: LaZagne
- First seen
- 2014-08-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Operating systems
- linux, macos, windows
- Related IoCs
- 11 (11 malicious)
- Last IoC activity
- 2026-08-20 10:55:46
- Profile updated
- 2026-07-07 12:49:17
Context
LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system. It has modules for Windows, Linux, and OSX, but is mainly focused on Windows systems. LaZagne is publicly available on GitHub.
Recent IoC activity
11 malicious indicators in Maltiverse are attributed to LaZagne (S0349). The 11 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | $RNL3V1B.exe | 2026-08-20 | 3 |
| file sample | 2026-08-16_11df3bd67eb3fa36557dfe7e0c7ee4c3_cobalt-strike_glassworm_icedid_la... | 2026-08-16 | 1 |
| file sample | 2026-08-13_74856f8cd033a25479a8edeb84c741ea_cobalt-strike_glassworm_icedid_la... | 2026-08-13 | 1 |
| file sample | 2026-08-12_e5c02a21b76fb563c0e713229ad45254_cobalt-strike_glassworm_icedid_la... | 2026-08-12 | 1 |
| file sample | 2026-08-11_81e6ce27a3ead8c626e584bd88b48402_cobalt-strike_glassworm_icedid_la... | 2026-08-11 | 1 |
| file sample | LaZane.exe | 2026-07-25 | 3 |
| file sample | 2026-07-03_0200528dbf3817456a165a7eb06eb81a_cobalt-strike_glassworm_icedid_la... | 2026-07-03 | 1 |
| file sample | 2026-07-02_b77f77ef26aef1db33ce4bf0da2bbafb_glassworm_lazagne_njrat | 2026-07-02 | 1 |
| file sample | 2026-04-16_cf3dfbcffab563e0923dd35803343798_cobalt-strike_elex_glassworm_hamm... | 2026-04-16 | 1 |
| file sample | CS2-Loader.exe | 2026-03-09 | 1 |
| file sample | file.exe | 2026-01-14 | 2 |
Detection coverage
- 1 YARA rules
- 133 Sigma rules
Malware & tools used
- Credentials In Files (attack-pattern)
- Windows Credential Manager (attack-pattern)
- LSA Secrets (attack-pattern)
- /etc/passwd and /etc/shadow (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- LSASS Memory (attack-pattern)
- Cached Domain Credentials (attack-pattern)
- Credentials from Password Stores (attack-pattern)
- Keychain (attack-pattern)
- Proc Filesystem (attack-pattern)
Used by threat actors
- Wizard Spider (threat-actor)
- Tonto Team (threat-actor)
- Scattered Spider (threat-actor)
- Inception (threat-actor)
- Evilnum (threat-actor)
- APT3 (threat-actor)
- APT33 (threat-actor)
- OilRig (threat-actor)
- MuddyWater (threat-actor)
- Leafminer (threat-actor)
- Akira (threat-actor)
- TeamTNT (threat-actor)
Detection rules
- SEKOIA_Hacktool_Lazagne_Strings (yara-rule)
Reports & references
- Kaspersky — 107610 (report)
- MITRE ATT&CK — G0100 (report)
- decoded.avast.io — Apt Group Targeting Governmental Agencies In East Asia (report)
- Cisco Talos — Uat 5918 Targets Critical Infra In Taiwan (report)
- Trend Micro — Ransomware Spotlight Ransomexx (report)
- yoroi.company — Shadows From The Past Threaten Italian Enterprises (report)
- thedfirreport.com — Seo Poisoning A Gootloader Story (report)
- marcoramilli.com — C2 Traffic Patterns Personal Notes (report)
- malpedia.caad.fkie.fraunhofer.de — Py.Lazagne (report)
- fourcore.io — Threat Hunting Browser Credential Stealing (report)
- github.com — Lazagne (report)
- edu.anarcho-copy.org — Group Ib%20Redcurl (report)
- Mandiant — Alphv Ransomware Backup (report)
- infinitumit.com.tr — Apt 35 (report)
- Trend Micro — Weaponizing Open Source Software For Targeted Attacks (report)
- MITRE ATT&CK — S0349 (report)