logo

Advanced Lazarus Memory-Only Toolset Deeply Analyzed by Fox-IT

ID: 07ffce26-d98c-54ac-a8e8-469675959659

STIX ID: report--07ffce26-d98c-54ac-a8e8-469675959659

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Ddos

...
...

## Executive Summary Security researchers identified a sophisticated Lazarus-linked cyber espionage campaign targeting international financial entities that uses a three-stage, memory-only framework (DPAPILoader -> RemotePELoader -> RemotePE). The operation leverages DPAPI-based environmental keying for staged decryption, HellsGate remapping and ETW patching to evade EDR, in-memory remote access with plugin support and secure file destruction, and Namecheap-hosted infrastructure with Microsoft-like HTTP cookie fields; defenders are advised to focus on host-based behavioral detection and targeted network hunting for IOCs such as lassvc.dll service names, DPAPI-encrypted blobs, and SNI/DNS artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.