Lazarus Expands Financial Espionage Operations With Memory-Resident RemotePE RAT

2026-05-29 Poly Swarm

https://blog.polyswarm.io/lazarus-expands-financial-espionage-operations-with-memory-resident-remotepe-rat

Thumbnail for Lazarus Expands Financial Espionage Operations With Memory-Resident RemotePE RAT

Lazarus-linked operators are using a three-stage malware framework, DPAPILoader, RemotePELoader, and RemotePE, to maintain stealthy long-term access in financial and cryptocurrency environments. DPAPILoader decrypts victim-bound payloads with Windows DPAPI and reflective loading, while RemotePELoader uses HellsGate/TartarusGate direct syscalls, clean DLL remapping, and ETW patching to reduce EDR telemetry before retrieving the in-memory RemotePE RAT. RemotePE provides encrypted C2, file and process operations, command execution, plugin loading, ZIP compression, exfiltration, and secure deletion, with operational patterns overlapping AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces activity. The report frames the framework as a selective, actor-in-the-loop Lazarus capability optimized for persistence, espionage, and eventual cryptocurrency theft or financial fraud.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 557551f8468b55e64af8969e71f9246f 2026-05-22 2026-05-22
HASH 6f15a1f78380d204f7f2369749c72b4b 2026-05-22 2026-05-22
HASH ac468b5536a0b3f8c6b88968a7f3761f 2026-05-22 2026-05-22
HASH 85766786fd00957737f1c88632ab9e0d 2025-09-01 2026-05-22
HASH 23c2569a65870a9e412d98d5b3bdc554 2025-09-01 2026-05-22
HASH 4f6ae0110cf652264293df571d66955… 2025-09-01 2025-09-01
HASH aa4a2d1215f864481994234f13ab485… 2025-09-01 2025-09-01
HASH 37f5afb9ed3761e73feb95daceb7a1f… 2025-09-01 2025-09-01

Related Actors

Related Reports

« Back