Skip to content

Malware

lsassDumper

This in Go written malware is lsass process memory dumper, which was custom developed by threat actors according to Security Joes.

lsassDumper is a Windows malware family.

Background

Written in Go, this malware is an lsass process memory dumper that, according to Security Joes, was purpose-built by threat actors. It can automatically upload the resulting dumps to the free file-transfer service "transfer.sh".


Source: Malpedia (Fraunhofer FKIE).