Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

The Lazarus Group, which has ties to North Korea, has been using a cross-platform malware known as RemotePE to target financial and cryptocurrency businesses, according to cybersecurity analysts.

According to Fox-IT, a division of the NCC Group, RemotePE is a component of a multi-stage assault chain that includes two loaders known as DPAPILoader and RemotePELoader.

Security researchers Yun Zheng Hu and Mick Koomen stated that DPAPILoader uses the Windows Data Protection API (DPAPI) to decrypt and load RemotePELoader from disk. “RemotePELoader advertises to a C2 server and waits for the next stage, which is RemotePE, a RAT that runs completely in memory and never writes to disk, leaving no filesystem artifacts.

The security provider first brought attention to RemotePE in September 2025 in relation to an attack that targeted an unidentified company in the decentralized finance (DeFi) industry read more about Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *