Hackers have injected malicious code into the legitimate Windows service, Windows Error Reporting (WER), as part of a fileless malware attack. The malicious code is injected into the service to evade detection, according to researchers at Malwarebytes.

Exploiting the WER service is not a new tactic, but, as Malwarebytes researchers Hossein Jazi and Jérôme Segura reported, this fileless malware attack is the work of an unknown hacking group aimed at espionage.
“The attackers compromised a site to host their payload and used the CactusTorch framework to execute a fileless attack, accompanied by several techniques that hinder analysis,” the report.
Spear-phishing for installing the payload
The attack was first observed on September 17, when researchers discovered phishing emails containing a malicious document in ZIP format.
The initial malicious payloads were installed on the computers via spear-phishing emails.
Upon opening the document, shellcode via a malicious macro identified as the CactusTorch VBA module, which loads a .NET payload directly into the memory of the now-infected Windows device.
The binary is then executed from the computer's memory, leaving no trace on the hard drive, by injecting the embedded shellcode into WerFault.exe, the Windows process of the WER service.

The same technique is used by other malware (Cerber ransomware and NetWire RAT) to avoid detection.
With malicious code injected into the Windows Error Reporting service thread, hackers check whether a debugger is being used on the target device or whether the payload is running in a virtual machine or sandbox. In short, they check whether detection techniques are being used.
If the malware feels “safe enough” to proceed to the next step, it will decrypt and load the final shellcode into a new WER thread, which will execute in a new thread.
The final malware payload hosted on asia-kotoba[.]net in the form of a fake favicon will be downloaded and injected into a new process.
The Malwarebytes researchers were unable to analyze the final payload.
Behind the fileless malware attack is likely APT32
Malwarebytes was unable to link the attack to a specific group. However, some of the breach indicators and tactics observed suggest that the APT32 (also known as OceanLotus and SeaLotusVietnamese government-backed ) espionage group is likely behind the attack . For example, APT32 is known to use the CactusTorch VBA module to distribute variants of Denis Rat.
Also, according to Bleeping Computer, a domain (yourrighttocompensation [.] Com) registered in Ho Chi Minh City, Vietnam, was used to host and distribute the phishing emails and malicious payloads
