logo

Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

ID: b5f73dd9-9766-5f8c-9ee8-c02824f9d3c6

STIX ID: report--b5f73dd9-9766-5f8c-9ee8-c02824f9d3c6

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: [email protected] (The Hacker News)

...
...

RemotePE is a cross-platform, memory-only remote access trojan (RAT) attributed to the North Korea-linked Lazarus Group and used in targeted campaigns against financial and cryptocurrency organizations. The attack chain uses a DPAPILoader DLL to decrypt and load a second-stage loader (RemotePELoader) which fetches and executes the RemotePE RAT in memory; the toolset includes EDR evasion techniques (e.g., Hell's Gate, ETW patching), environmental keying, and file-wiping behavior observed in related RATs. Fox-IT/F-IT analysts observed active development from mid-2023 to mid-2024 and note the toolset's low detection rate and suitability for long-term stealthy access to high-value targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.