LaZagne — Malware Profile
LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system. It has modules for Windows, Linux, and OSX, but is mainly focused on Windows systems. LaZagne is publicly available on GitHub.
MITRE ATT&CK techniques (10)
- T1003.001 LSASS Memory
- T1003.004 LSA Secrets
- T1003.005 Cached Domain Credentials
- T1003.007 Proc Filesystem
- T1003.008 /etc/passwd and /etc/shadow
- T1552.001 Credentials In Files
- T1555 Credentials from Password Stores
- T1555.001 Keychain
- T1555.003 Credentials from Web Browsers
- T1555.004 Windows Credential Manager
Attributed threat actors
- Conti
- APT3
- Scattered Spider
- OilRig
- MuddyWater
- Inception
- APT33
- TeamTNT
- Tonto Team
- Evilnum
- Leafminer
- AvosLocker machine-inferred link
- ALPHV/BlackCat machine-inferred link
- 8Base machine-inferred link
- Akira