Dpapi is a tool tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed January 5, 2026; most recent activity July 17, 2026.
Dpapi, short for Data Protection API, refers to the Windows cryptographic API used to protect and decrypt data tied to a user or machine. In threat intelligence, attackers and credential-stealer families often leverage DPAPI-related capabilities to access or decrypt sensitive data such as browser credentials, tokens, and cookies stored on infected hosts; obfuscation and stealth techniques are commonly employed to evade detection.
From late April to mid-June 2026, ACR Stealer, a malware-as-a-service operation, has ramped up its activity targeting enterprise users by stealing browser credentials, session tokens, and sensitive documents. The attack…
VVS Stealer is a Python-based malware designed to steal Discord credentials and tokens. It has been available for purchase on Telegram since at least April 2025, posing a risk to Discord users. Palo Alto Networks…