Lazarus Expands Financial Espionage Operations With Memory-Resident RemotePE RAT

2026-05-29 Poly Swarm

https://blog.polyswarm.io/lazarus-expands-financial-espionage-operations-with-memory-resident-remotepe-rat

Thumbnail for Lazarus Expands Financial Espionage Operations With Memory-Resident RemotePE RAT

Lazarus-linked operators are using a three-stage malware framework, DPAPILoader, RemotePELoader, and RemotePE, to maintain stealthy long-term access in financial and cryptocurrency environments. DPAPILoader decrypts victim-bound payloads with Windows DPAPI and reflective loading, while RemotePELoader uses HellsGate/TartarusGate direct syscalls, clean DLL remapping, and ETW patching to reduce EDR telemetry before retrieving the in-memory RemotePE RAT. RemotePE provides encrypted C2, file and process operations, command execution, plugin loading, ZIP compression, exfiltration, and secure deletion, with operational patterns overlapping AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces activity. The report frames the framework as a selective, actor-in-the-loop Lazarus capability optimized for persistence, espionage, and eventual cryptocurrency theft or financial fraud.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 710f15302859c7af1c1e25219d70484… 2026-05-22 2026-05-29
HASH 62e040a32aac2d2faa8d2bffa2cf7ab… 2026-05-22 2026-05-29
HASH 6b33d20196267b0d64bca815ca86355… 2026-05-22 2026-05-29
HASH 7a05188ab0129b0b4f38e2e7599c5c5… 2025-09-01 2026-05-29
HASH 159471e1abc9adf6733af9d24781fbf… 2025-09-01 2026-05-29
HASH 4f6ae0110cf652264293df571d66955… 2025-09-01 2026-05-29
HASH aa4a2d1215f864481994234f13ab485… 2025-09-01 2026-05-29
HASH 37f5afb9ed3761e73feb95daceb7a1f… 2025-09-01 2026-05-29

Related Actors

Related Reports

« Back