RemotePE: The Lazarus RAT that lives in memory
2026-05-22 • Foxit •
https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/
Fox-IT analyzed a Lazarus subgroup toolset used against financial and cryptocurrency organizations, overlapping with activity linked to AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces. The intrusion chain uses DPAPILoader to decrypt victim-bound payloads with Windows DPAPI, RemotePELoader to retrieve the next stage from C2, and RemotePE as a full RAT that runs entirely in memory. The tooling applies environmental keying, reflective loading, HellsGate/TartarusGate-style syscall resolution, DLL unhooking, ETW patching, encrypted HTTP C2, plugin loading, file and process control, and secure deletion behavior. Fox-IT reports Namecheap-hosted C2 domains, host artifacts, sample hashes, and YARA rules, making the findings relevant for detecting low-footprint Lazarus observation campaigns that may precede data theft or financial operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| YARA | Lazarus_RemotePE_DPAPI_Encrypte… | 2026-05-22 | 2026-05-22 |
| YARA | Lazarus_RemotePE_class_strings | 2026-05-22 | 2026-05-22 |
| YARA | Lazarus_RemotePE_C2_strings | 2026-05-22 | 2026-05-22 |
| YARA | Lazarus_DPAPILoader_Hunting | 2026-05-22 | 2026-05-22 |
| HASH | 557551f8468b55e64af8969e71f9246f | 2026-05-22 | 2026-05-22 |
| HASH | 6f15a1f78380d204f7f2369749c72b4b | 2026-05-22 | 2026-05-22 |
| HASH | ac468b5536a0b3f8c6b88968a7f3761f | 2026-05-22 | 2026-05-22 |
| HASH | 781e02b32ed5dff6e512d9850a5b5403 | 2026-05-22 | 2026-05-22 |
| HASH | 75a46b23825ce7aa4ca297d93450f4e2 | 2026-05-22 | 2026-05-22 |
| HASH | 40c45ad6fef563af8a73dd48a38dc8ba | 2026-05-22 | 2026-05-22 |
| DOMAIN | devicelinkintel.com | 2026-05-22 | 2026-05-22 |
| DOMAIN | intelcloudinsights.com | 2026-05-22 | 2026-05-22 |
| DOMAIN | akamaicloud.com | 2026-05-22 | 2026-05-22 |
| DOMAIN | msdeliverycontent.com | 2026-05-22 | 2026-05-22 |
| DOMAIN | livedrivefiles.com | 2026-05-22 | 2026-05-22 |
| HASH | 85766786fd00957737f1c88632ab9e0d | 2025-09-01 | 2026-05-22 |
| HASH | 23c2569a65870a9e412d98d5b3bdc554 | 2025-09-01 | 2026-05-22 |
| DOMAIN | aes-secure.net | 2025-09-01 | 2026-05-22 |
| DOMAIN | azureglobalaccelerator.com | 2025-09-01 | 2026-05-22 |