An updated DPAPISnoop build draws attention to a narrow but important attack surface: Windows CREDHIST files can yield offline-crackable hashes that may reveal fragments of password history.
A loader chain built around Windows DPAPI and in-memory execution points to a quieter, harder-to-hunt style of intrusion against finance and crypto targets.