Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms
ID: b5f73dd9-9766-5f8c-9ee8-c02824f9d3c6
STIX ID: report--b5f73dd9-9766-5f8c-9ee8-c02824f9d3c6
Feed Name: The Hacker News
RemotePE is a cross-platform, memory-only remote access trojan (RAT) attributed to the North Korea-linked Lazarus Group and used in targeted campaigns against financial and cryptocurrency organizations. The attack chain uses a DPAPILoader DLL to decrypt and load a second-stage loader (RemotePELoader) which fetches and executes the RemotePE RAT in memory; the toolset includes EDR evasion techniques (e.g., Hell's Gate, ETW patching), environmental keying, and file-wiping behavior observed in related RATs. Fox-IT/F-IT analysts observed active development from mid-2023 to mid-2024 and note the toolset's low detection rate and suitability for long-term stealthy access to high-value targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
