Lazarus APT unveils fileless remote access Trojan designed to evade detection
ID: f240ab7c-a050-5554-8208-5c9b8f8b5c59
STIX ID: report--f240ab7c-a050-5554-8208-5c9b8f8b5c59
Feed Name: Security Affairs
Threat Score
North Korea-linked Lazarus developed and deployed a three-stage toolchain (DPAPILoader -> RemotePELoader -> RemotePE) that uses DPAPI-bound encrypted blobs and fully in-memory execution to evade detection and forensic recovery; researchers found active C2 servers, live samples, and operator-controlled payload delivery consistent with targeted, long-term observation and sophisticated financially motivated operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
