Researchers demonstrated that the Microsoft-signed Windows Error Reporting Dump Encoding Library, WerEnc.dll, can be modified in memory to encrypt attacker data using an attacker-controlled RSA public key. The bring-your-own-key (BYOK) technique replaces the DLL's embedded Microsoft RSA-4096 public-key blob after changing memory protections, then calls EncryptDumpFile or EncryptDumpStream to create AES-256-CBC-encrypted containers. The AES session key and IV are RSA-wrapped to the substituted public key, allowing only the attacker-held private key to decrypt the output.
Public proof-of-concept tooling reportedly supports key generation, local encryption and decryption, payload execution, and optional HTTP retrieval of BYOK keys or encrypted implants from command-and-control infrastructure. This living-off-the-land method can reduce malware cryptographic code and make protected payloads resemble Windows Error Reporting artifacts. Defenders should investigate unexpected WerEnc.dll loads by non-error-reporting processes, memory-protection changes affecting the library, suspicious creation of encrypted dump-like files, and related outbound network activity.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
On September 15, 2026, 0xsp published research describing replacement of WerEnc.dll's embedded RSA public key in memory so its dump-encryption functions encrypt data for an attacker-controlled key. The disclosure included public proof-of-concept tooling for key generation, DLL patching, encryption/decryption, execution, and optional HTTP-based retrieval of encrypted payloads.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourceipurple.team
Open sourcecyberveille.ch
Open source0xsp.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.