logo

LetMeowIn - Analysis of a Credential Dumper

ID: 4a7766a0-d292-530e-809f-b93571723002

STIX ID: report--4a7766a0-d292-530e-809f-b93571723002

Feed Name: Binary Defense Blog

Threat Score
70/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

ARC Labs analyzes LetMeowIn, a Windows LSASS credential-dumping tool that leverages MiniDumpWriteDump with in-memory manipulation and multiple evasion techniques (API obfuscation, indirect syscalls, ETW tampering, hijacking existing LSASS handles via NtDuplicateObject, and corrupting dump signatures) to bypass endpoint security; the report confirms the tool can dump LSASS while EDRs are present and provides practical detection recommendations including process creation and Sysmon monitoring, handle-manipulation auditing, registry SACLs for MiniDumpAuxiliaryDlls, and heuristics for dump file creation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.