LsaRecorder
LsaRecorder is a credential-theft tool used by the intrusion cluster tracked by Palo Alto Networks Unit 42 as CL-UNK-1068 (assessed as a Chinese-linked/Chinese-speaking actor). In reported intrusions, LsaRecorder is used to capture Windows logon credentials by hooking the LSA authentication callback function LsaApLogonUserEx2 to record the WinLogon password. It is part of a broader credential-access toolkit observed in this campaign alongside Mimikatz and memory-dumping workflows (e.g., DumpIt/Volatility). The activity described occurs in long-running compromises of organizations across South, Southeast, and East Asia, targeting sectors including telecommunications, energy, technology, pharmaceuticals, government, and law enforcement, consistent with an espionage-oriented operation.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Other tools powering CL-UNK-1068's credential theft activities include Mimikatz, LsaRecorder, DumpItForLinux, Volatility Framework, and the SQL Server Management Studio Password Export Tool.
Techniques & procedures
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Credential Access
3 techniques"Other tools powering CL-UNK-1068's credential theft activities include Mimikatz, LsaRecorder, DumpItForLinux, Volatility Framework, and the SQL Server Management Studio Password Export Tool."
"...credential theft activities include Mimikatz, LsaRecorder..."
Collection
1 techniqueRecent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used for credential theft activities (credential access) in the described intrusion set.
Credential theft tool that hooks Windows authentication routines to capture logon passwords.
Password capture/credential theft tool used to obtain credentials from Windows systems.
Windows credential theft tool that hooks LSA authentication callback (LsaApLogonUserEx2) to capture users’ logon passwords.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.