RemotePE: The Lazarus RAT that lives in memory

2026-05-22 Foxit

https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/

Thumbnail for RemotePE: The Lazarus RAT that lives in memory

Fox-IT analyzed a Lazarus subgroup toolset used against financial and cryptocurrency organizations, overlapping with activity linked to AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces. The intrusion chain uses DPAPILoader to decrypt victim-bound payloads with Windows DPAPI, RemotePELoader to retrieve the next stage from C2, and RemotePE as a full RAT that runs entirely in memory. The tooling applies environmental keying, reflective loading, HellsGate/TartarusGate-style syscall resolution, DLL unhooking, ETW patching, encrypted HTTP C2, plugin loading, file and process control, and secure deletion behavior. Fox-IT reports Namecheap-hosted C2 domains, host artifacts, sample hashes, and YARA rules, making the findings relevant for detecting low-footprint Lazarus observation campaigns that may precede data theft or financial operations.

Indicators of Compromise

Type Value First Seen Last Seen
YARA Lazarus_RemotePE_DPAPI_Encrypte… 2026-05-22 2026-05-22
YARA Lazarus_RemotePE_class_strings 2026-05-22 2026-05-22
YARA Lazarus_RemotePE_C2_strings 2026-05-22 2026-05-22
YARA Lazarus_DPAPILoader_Hunting 2026-05-22 2026-05-22
HASH 557551f8468b55e64af8969e71f9246f 2026-05-22 2026-05-22
HASH 6f15a1f78380d204f7f2369749c72b4b 2026-05-22 2026-05-22
HASH ac468b5536a0b3f8c6b88968a7f3761f 2026-05-22 2026-05-22
HASH 781e02b32ed5dff6e512d9850a5b5403 2026-05-22 2026-05-22
HASH 75a46b23825ce7aa4ca297d93450f4e2 2026-05-22 2026-05-22
HASH 40c45ad6fef563af8a73dd48a38dc8ba 2026-05-22 2026-05-22
DOMAIN devicelinkintel.com 2026-05-22 2026-05-22
DOMAIN intelcloudinsights.com 2026-05-22 2026-05-22
DOMAIN akamaicloud.com 2026-05-22 2026-05-22
DOMAIN msdeliverycontent.com 2026-05-22 2026-05-22
DOMAIN livedrivefiles.com 2026-05-22 2026-05-22
HASH 85766786fd00957737f1c88632ab9e0d 2025-09-01 2026-05-22
HASH 23c2569a65870a9e412d98d5b3bdc554 2025-09-01 2026-05-22
DOMAIN aes-secure.net 2025-09-01 2026-05-22
DOMAIN azureglobalaccelerator.com 2025-09-01 2026-05-22

Related Actors

Related Reports

« Back