logo

Lazarus APT unveils fileless remote access Trojan designed to evade detection

ID: f240ab7c-a050-5554-8208-5c9b8f8b5c59

STIX ID: report--f240ab7c-a050-5554-8208-5c9b8f8b5c59

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Pierluigi Paganini

...
...

North Korea-linked Lazarus developed and deployed a three-stage toolchain (DPAPILoader -> RemotePELoader -> RemotePE) that uses DPAPI-bound encrypted blobs and fully in-memory execution to evade detection and forensic recovery; researchers found active C2 servers, live samples, and operator-controlled payload delivery consistent with targeted, long-term observation and sophisticated financially motivated operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.