RemotePE: The Lazarus RAT that lives in memory

2026-05-22 Foxit

https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/

Thumbnail for RemotePE: The Lazarus RAT that lives in memory

Fox-IT analyzed a Lazarus subgroup toolset used against financial and cryptocurrency organizations, overlapping with activity linked to AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces. The intrusion chain uses DPAPILoader to decrypt victim-bound payloads with Windows DPAPI, RemotePELoader to retrieve the next stage from C2, and RemotePE as a full RAT that runs entirely in memory. The tooling applies environmental keying, reflective loading, HellsGate/TartarusGate-style syscall resolution, DLL unhooking, ETW patching, encrypted HTTP C2, plugin loading, file and process control, and secure deletion behavior. Fox-IT reports Namecheap-hosted C2 domains, host artifacts, sample hashes, and YARA rules, making the findings relevant for detecting low-footprint Lazarus observation campaigns that may precede data theft or financial operations.

Indicators of Compromise

Type Value First Seen Last Seen
YARA Lazarus_RemotePE_DPAPI_Encrypte… 2026-05-22 2026-06-23
YARA Lazarus_RemotePE_class_strings 2025-09-01 2026-06-23
YARA Lazarus_RemotePE_C2_strings 2025-09-01 2026-06-23
YARA Lazarus_DPAPILoader_Hunting 2025-09-01 2026-06-23
HASH 710f15302859c7af1c1e25219d70484… 2026-05-22 2026-05-29
HASH 62e040a32aac2d2faa8d2bffa2cf7ab… 2026-05-22 2026-05-29
HASH 6b33d20196267b0d64bca815ca86355… 2026-05-22 2026-05-29
HASH 7a05188ab0129b0b4f38e2e7599c5c5… 2025-09-01 2026-05-29
HASH 159471e1abc9adf6733af9d24781fbf… 2025-09-01 2026-05-29
HASH 37f5afb9ed3761e73feb95daceb7a1f… 2026-05-22 2026-05-22
HASH aa4a2d1215f864481994234f13ab485… 2026-05-22 2026-05-22
HASH 4f6ae0110cf652264293df571d66955… 2026-05-22 2026-05-22
DOMAIN devicelinkintel.com 2026-05-22 2026-05-22
DOMAIN intelcloudinsights.com 2026-05-22 2026-05-22
DOMAIN akamaicloud.com 2026-05-22 2026-05-22
DOMAIN msdeliverycontent.com 2026-05-22 2026-05-22
DOMAIN livedrivefiles.com 2026-05-22 2026-05-22
DOMAIN aes-secure.net 2025-09-01 2026-05-22
DOMAIN azureglobalaccelerator.com 2025-09-01 2026-05-22

Related Actors

Related Reports

« Back