Abuse of wermgr.exe for Named Pipe Communication
Malware families like Qakbot and Trickbot inject malicious code into the legitimate Windows Error Reporting process (wermgr.exe) to establish covert named pipe communication for C2 and persistence.
The wermgr.exe process, which is the legitimate Windows Error Reporting application, is frequently targeted by sophisticated malware families including Qakbot and Trickbot. Because wermgr.exe is a trusted system binary, threat actors use process injection techniques to execute malicious code within its memory space. A primary goal of this injection is to facilitate covert inter-process communication using Windows named pipes. This allows the injected code to bypass standard monitoring or establish persistent command-and-control channels without immediately triggering process-based alerts associated with unknown binaries. Detection of wermgr.exe creating or connecting to named pipes is a highly reliable indicator of malicious activity, as the process does not typically require this capability for its intended reporting function.
Impact
Successful exploitation allows attackers to maintain stealthy persistence and facilitate command-and-control communication within a compromised Windows environment. By masking malicious traffic behind the Windows Error Reporting process, attackers can complicate host-based forensics and evade standard security controls, potentially leading to unauthorized privilege escalation or lateral movement.
Recommendation
Deploy the provided Sigma rule to monitor for anomalous named pipe activity originating from wermgr.exe on all Windows endpoints. Ensure Sysmon Event ID 17 (Pipe Created) and 18 (Pipe Connected) are enabled to provide the necessary telemetry for this detection. When an alert fires, prioritize investigating the process lineage of wermgr.exe to identify the source of the initial injection.
Immediate actions
Deploy Sigma detection for wermgr.exe named pipe activity
Mitigations
Review process injection protections and EDR/Sysmon coverage
T1071
Detection coverage 1
Detect Suspicious wermgr.exe Named Pipe Activity
mediumDetects the wermgr.exe process creating or connecting to a named pipe, which is a common technique used by malware like Qakbot to facilitate covert communication.
Detection queries are available on the platform. Get full rules →