Target Industry

Indiscriminate, opportunistic targeting.

Overview

Threat actors are exploiting a legacy Windows tool, WerFaultSecure.exe, to extract cached passwords from the Local Security Authority Subsystem Service (LSASS) on fully updated Windows 11 24H2 systems. WerFaultSecure.exe is a diagnostic utility used by Windows to collect crash reports from applications and system processes. It runs with Windows Trusted Computing Base (WinTCB) Protected Process Light (PPL) privileges, a security model designed to restrict access to sensitive system components.  

These privileges ensure that only trusted, signed binaries can interact with the process, significantly reducing the risk of tampering or credential theft. Because of its PPL status, the process can access protected memory regions, including those used by LSASS a critical Windows component responsible for enforcing security policies, handling authentication, and storing sensitive credential material. 

Impact

The exploitation of WerFaultSecure.exe can have serious consequences for organisations, including unauthorised access to sensitive data, financial losses resulting from credential theft, and potential disruption to operations. The ability to extract credentials from LSASS enables lateral movement within networks, significantly increasing the risk of further compromise. 

Affected Products

This has been seen to affect fully patched Windows 11 24H2 systems.

Exploitation

Threat actors use a custom loader called WSASS to run WerFaultSecure.exe with special command-line switches. These switches allow them to target LSASS and save its memory dump unencrypted. The threat actors then modify the file header to make it look like a harmless image file, helping it evade antivirus detection. Once threat actors have the LSASS dump, they can extract New Technology LAN Manager (NTLM) hashes and plaintext passwords. After NTLM hashes and plaintext credentials have been extracted from an LSASS memory dump, a series of post-exploitation steps to expand access, maintain persistence, and escalate privileges across the target environment. 

Containment, Mitigations & Remediations 

To mitigate the risk of exploitation, organisations should ensure that all systems are updated with the latest security patches from Microsoft. Monitoring the execution of WerFaultSecure.exe and implementing strict access controls can help prevent unauthorised access. Additionally, organisations should consider employing endpoint detection and response (EDR) solutions to identify and respond to suspicious activities related to LSASS memory access. Regular security audits and employee training on recognising phishing attempts can further reduce the risk of initial compromise. There is currently no patch available.  

Threat Landscape

The threat landscape surrounding the exploitation of WerFaultSecure.exe is characterised by a mix of opportunistic and targeted attacks. Threat actors are motivated by financial gain, data theft, and espionage. The increasing sophistication of these attacks highlights the need for organisations to remain vigilant and proactive in their cyber security measures. 

Threat Group

At this time, there is no specific threat group confirmed to be exploiting this flaw. However, the sophistication of the technique suggests it could be the work of a nation-state advanced persistent threat (APT) group or financially motivated groups with advanced capabilities. 

Tactics, Techniques and Procedures (TTPs) 

  • T1587: Develop Capabilities 
  • T1036.005: Masquerading: Match Legitimate Resource Name or Location 
  • T1003.001: OS Credential Dumping: LSASS Memory 

Further Information

Cyber Security News article 

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content