WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Threat Awareness – Threat Actors Exploit Windows Error Reporting Tool to Deploy Malware
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – Threat Actors Exploit Windows Error Reporting Tool to Deploy Malware

Author: Alec Davison

Created: Thursday, January 5, 2023 - 20:02

Categories: Cybersecurity

Threat actors are actively exploiting the Windows Problem Reporting (WerFault.exe) error reporting tool for Windows to load malware into a compromised system’s memory using a DLL sideloading technique, according to researchers at K7 Security Labs.

Abusing a legitimate Windows executable allows attackers to infect devices without raising any alarms. This particular attack is reportedly delivered via an email that contains an ISO attachment. The malware downloaded in this campaign is the Pupy Remote Access Trojan (RAT) which allows threat actors to gain full access to infected devices, enabling them to execute commands, steal data, install further malware, or spread laterally through a network. As an open-source tool, it has been used by several state-backed cyber groups like the Iranian APT33 and APT35 groups. Likewise, QBot malware threat actors have been observed using a similar attack chain last summer, exploiting the Windows Calculator to evade detection by security software. Read more at BleepingComputer.

Related Resources

Members Only

(TLP:AMBER) New IOCs (Stryker) and Malware Analysis Report (F5 BIG-IP)

Jun 5, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) EPA to Conduct 2026 National Cyber Drill Focused on Operating Without Telecommunications and Internet Connectivity

Jun 4, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) CISA and Partners Urge Hardening Automatic Tank Gauge Systems

Jun 4, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar