Researchers reported a malware campaign that abuses the legitimate Windows Error Reporting binary WerFault.exe to stealthily deploy Pupy RAT through DLL sideloading. The infection chain begins with a phishing email carrying an ISO attachment that contains WerFault.exe, a malicious faultrep.dll, a decoy XLS file, and a shortcut file that launches the payload via scriptrunner.exe and cmd. Because WerFault.exe is a Microsoft-signed binary, the technique helps the malware blend in with normal system activity and reduce suspicion from security tools.
Analysis showed the malicious DLL uses a custom API resolver, spawns threads to open the lure spreadsheet, decrypts an embedded overlay with RC4 using SystemFunction032, and loads the decrypted PE directly into memory as Pupy RAT. The RAT was observed attempting to reach a command-and-control server at 103.79.76.40, although the server was offline during examination. Researchers said attribution remains unconfirmed, but the Chinese-language lure and other indicators suggest the operators may be China-based or targeting victims in China; the use of Pupy RAT also raises concern because the open-source remote access trojan has previously been linked to espionage activity and enables full device compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
K7 Security Labs analyzed a malware campaign in which attackers used a phishing-delivered ISO to abuse the legitimate Windows Error Reporting binary WerFault.exe, sideload a malicious faultrep.dll, and execute Pupy RAT in memory. The researchers assessed that the lure content suggested likely targeting in China, though attribution to a specific actor was not confirmed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.