Lazarus Expands Financial Espionage Operations With Memory-Resident RemotePE RAT
2026-05-29 • Poly Swarm •
Lazarus-linked operators are using a three-stage malware framework, DPAPILoader, RemotePELoader, and RemotePE, to maintain stealthy long-term access in financial and cryptocurrency environments. DPAPILoader decrypts victim-bound payloads with Windows DPAPI and reflective loading, while RemotePELoader uses HellsGate/TartarusGate direct syscalls, clean DLL remapping, and ETW patching to reduce EDR telemetry before retrieving the in-memory RemotePE RAT. RemotePE provides encrypted C2, file and process operations, command execution, plugin loading, ZIP compression, exfiltration, and secure deletion, with operational patterns overlapping AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces activity. The report frames the framework as a selective, actor-in-the-loop Lazarus capability optimized for persistence, espionage, and eventual cryptocurrency theft or financial fraud.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 557551f8468b55e64af8969e71f9246f | 2026-05-22 | 2026-05-22 |
| HASH | 6f15a1f78380d204f7f2369749c72b4b | 2026-05-22 | 2026-05-22 |
| HASH | ac468b5536a0b3f8c6b88968a7f3761f | 2026-05-22 | 2026-05-22 |
| HASH | 85766786fd00957737f1c88632ab9e0d | 2025-09-01 | 2026-05-22 |
| HASH | 23c2569a65870a9e412d98d5b3bdc554 | 2025-09-01 | 2026-05-22 |
| HASH | 4f6ae0110cf652264293df571d66955… | 2025-09-01 | 2025-09-01 |
| HASH | aa4a2d1215f864481994234f13ab485… | 2025-09-01 | 2025-09-01 |
| HASH | 37f5afb9ed3761e73feb95daceb7a1f… | 2025-09-01 | 2025-09-01 |