Most Viewed Content:

OpenAI Launched Assistants API, Allowing Developers to Customize AI Assistants with One Click

At today's OpenAI's first developer conference, OpenAI launched the...

Microsoft working on new features for Win11 / Win12: smart notifications, depth-of-field effects

According to the source Albacore (@thebookisclosed), Microsoft is preparing...

India’s censorship body gave power to remove pirated Movies from platforms

India’s Ministry of Information and Broadcasting announced that its...

Microsoft Windows 10 / 11 to run malware via DLL side loading techniques

Hackers have abused the Windows Problem Reporting (WerFault.exe), a built-in error reporting tool in Microsoft Win10 / Win11, to run malware on the memory of infected devices via DLL side-loading technology.

The hacker first launches the malware through a legitimate Windows executable file, the whole process does not trigger any warnings and thus covertly infects the device. K7 Security Labs security company was the first to discover this attack method.

The malware campaign begins with an email with an ISO attachment. After double-clicking on the ISO file, the user mounts itself as a new drive letter containing a legitimate copy of the Windows WerFault.exe executable, a DLL file (“faultrep.dll”), an XLS file ( “File.xls”) and a shortcut file (‘inventory & our specialties.lnk’).

The victim launched the infection chain by clicking on the shortcut file, which uses “scriptrunner.exe” to execute WerFault.exe. WerFault is the standard Windows error reporting tool used in Windows 10 and 11, allowing the system to track and report errors. WerFault is a standard Windows error reporting tool used in Windows 10 and 11 that allows the system to track and report errors related to the operating system or applications.

Anti-virus tools usually trust WerFault because it is a legitimate Windows executable file signed by Microsoft, so launching it on a system will not usually trigger an alert to warn victims.

After launching WerFault.exe, the malware will use a known DLL sideloading flaw to load the malicious ‘failrep.dll’ DLL contained in the ISO.

Normally, the ‘faultrep.dll’ file is a legitimate DLL that Microsoft needs in the C:\Windows\System32 folder for WerFault to run correctly; however, the malicious DLL version in the ISO contains additional code that is used to launch the malware.

Latest

2024 Beijing Auto Show: All-new Toyota Crown unveiled at the booth

At the Beijing Auto Show, which opened on April...

Teclast P50 Tablet released: Pre-installed with Android 14, Unisoc T606 processor

Teclast today officially announced the launch of its P50...

Nissan’s global sales in March were 365,845 units, YOY increase of 3.3%

Nissan announced the latest production and sales data: global...

Skyworth EV6 II super-charging car 2024 model launched: Starting from 139,800 RMB

The 2024 Skyworth EV6 II car was officially launched...

Newsletter

Don't miss

2024 Beijing Auto Show: All-new Toyota Crown unveiled at the booth

At the Beijing Auto Show, which opened on April...

Teclast P50 Tablet released: Pre-installed with Android 14, Unisoc T606 processor

Teclast today officially announced the launch of its P50...

Nissan’s global sales in March were 365,845 units, YOY increase of 3.3%

Nissan announced the latest production and sales data: global...

Skyworth EV6 II super-charging car 2024 model launched: Starting from 139,800 RMB

The 2024 Skyworth EV6 II car was officially launched...

Kia Sonet SUV launched with optional L2 smart driving assistance

Kia's entry-level SUV Sonet Motors was officially launched at...
James Lopez
James Lopezhttps://www.techgoing.com
James Lopez joined Techgoing as Senior News Editor in 2022. He's been a tech blogger since before the word was invented, and will never log off.

Formula Leopard Super 9 officially unveiled at the 2024 Beijing Auto Show

The SUPER 9, which was just unveiled at the Formula brand’s spring launch not long ago, was also unveiled at the Beijing Auto Show...

Preview of Volkswagen’s new concept car debuting at Beijing Auto Show

Recently, we learned from the official Volkswagen China that on the eve of the opening of the Beijing Auto Show on April 24, Volkswagen...

Google confirms Android will switch to libdav1d codec to improve support for AV1 videos

Android system development manager Arif Dikici confirmed yesterday that the Play System update released in March 2024 has switched to VideoLAN’s open source libdav1d...