Comment by charcircuit

3 hours ago

>Data Protection API do meaningfully reduce what you can extract from a windows system

It's not meaningfully reduced. The stealer just has to call CryptUnprotectData before uploading it. It's not even like it will show a suspicious prompt to the user, without having to do anything extra the stealer can silently decrypt it.

I agree with the rest of the post though.