Target Industry
Indiscriminate, opportunistic targeting.
Overview
Threat actors are exploiting a legacy Windows tool, WerFaultSecure.exe, to extract cached passwords from the Local Security Authority Subsystem Service (LSASS) on fully updated Windows 11 24H2 systems. WerFaultSecure.exe is a diagnostic utility used by Windows to collect crash reports from applications and system processes. It runs with Windows Trusted Computing Base (WinTCB) Protected Process Light (PPL) privileges, a security model designed to restrict access to sensitive system components.
These privileges ensure that only trusted, signed binaries can interact with the process, significantly reducing the risk of tampering or credential theft. Because of its PPL status, the process can access protected memory regions, including those used by LSASS a critical Windows component responsible for enforcing security policies, handling authentication, and storing sensitive credential material.
Impact
The exploitation of WerFaultSecure.exe can have serious consequences for organisations, including unauthorised access to sensitive data, financial losses resulting from credential theft, and potential disruption to operations. The ability to extract credentials from LSASS enables lateral movement within networks, significantly increasing the risk of further compromise.
Affected Products
This has been seen to affect fully patched Windows 11 24H2 systems.
Exploitation
Threat actors use a custom loader called WSASS to run WerFaultSecure.exe with special command-line switches. These switches allow them to target LSASS and save its memory dump unencrypted. The threat actors then modify the file header to make it look like a harmless image file, helping it evade antivirus detection. Once threat actors have the LSASS dump, they can extract New Technology LAN Manager (NTLM) hashes and plaintext passwords. After NTLM hashes and plaintext credentials have been extracted from an LSASS memory dump, a series of post-exploitation steps to expand access, maintain persistence, and escalate privileges across the target environment.
Containment, Mitigations & Remediations
To mitigate the risk of exploitation, organisations should ensure that all systems are updated with the latest security patches from Microsoft. Monitoring the execution of WerFaultSecure.exe and implementing strict access controls can help prevent unauthorised access. Additionally, organisations should consider employing endpoint detection and response (EDR) solutions to identify and respond to suspicious activities related to LSASS memory access. Regular security audits and employee training on recognising phishing attempts can further reduce the risk of initial compromise. There is currently no patch available.
Threat Landscape
The threat landscape surrounding the exploitation of WerFaultSecure.exe is characterised by a mix of opportunistic and targeted attacks. Threat actors are motivated by financial gain, data theft, and espionage. The increasing sophistication of these attacks highlights the need for organisations to remain vigilant and proactive in their cyber security measures.
Threat Group
At this time, there is no specific threat group confirmed to be exploiting this flaw. However, the sophistication of the technique suggests it could be the work of a nation-state advanced persistent threat (APT) group or financially motivated groups with advanced capabilities.
Tactics, Techniques and Procedures (TTPs)
- T1587: Develop Capabilities
- T1587.001: Develop Capabilities: Malware
- T1036.005: Masquerading: Match Legitimate Resource Name or Location
- T1003.001: OS Credential Dumping: LSASS Memory
Further Information
Intelligence Terminology Yardstick












