
How Hackers Steal Passwords
Source: YouTube · John Hammond · published May 9, 2025 · 22:56
Hackers exploit Windows' Data Protection API (DP API) to steal encrypted passwords stored in browsers and system credentials 0:17.
Key Takeaways:
• DP API encrypts passwords locally using user or machine-specific keys, making them accessible to malware if the encryption key is obtained 2:43.
• Tools like Mimi Cats and Sharp DP API can extract passwords by leveraging DP API’s encrypted blobs, especially from Chrome, Brave, and Edge 5:58.
• Malware such as Lasagna and Nuroft actively targets DP API to recover passwords, including browser credentials and RDP keys 19:38.
• Passwords are stored in encrypted files within the user’s AppData directory, accessible via the local state file in browser profiles 12:24.
Understanding these tools and techniques helps improve endpoint security and awareness of credential theft methods.
Sources:
- 0:17 Introduction to DP API and password storage in Windows
- 2:43 DP API scopes and encryption tied to user or machine
- 5:58 Mimi Cats usage to extract browser passwords
- 12:24 Locating encrypted keys in browser profile files
- 19:38 Lasagna malware extracting master keys and passwords
- 21:44 Overview of password recovery tools like Nuroft and Web Browser Pass View
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
How do hackers steal passwords? Like when malware runs on your computer, it's looking for those stored and cached passwords that are saved to the file system. They're written to disk, but they are encrypted. So, how do hackers decrypt them? Well, in this video, I want to talk a little bit about DP API or the data protection API that modern Windows uses to be able to store and easily retrieve encrypted passwords. And this is something that we can play with. So I'm inside of my Windows 11 virtual machine and I'm going to open up a terminal and I'll run this as an administrator. Just rightclick to run as administrator or control shift enter. We'll have our user account control pop up. I'll just hit yes. I'll F11 to full screen that. And now let's say that I had my simple plain text password. …