RemotePE: The Lazarus RAT that lives in memory
2026-05-22 • Foxit •
https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/
Fox-IT analyzed a Lazarus subgroup toolset used against financial and cryptocurrency organizations, overlapping with activity linked to AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces. The intrusion chain uses DPAPILoader to decrypt victim-bound payloads with Windows DPAPI, RemotePELoader to retrieve the next stage from C2, and RemotePE as a full RAT that runs entirely in memory. The tooling applies environmental keying, reflective loading, HellsGate/TartarusGate-style syscall resolution, DLL unhooking, ETW patching, encrypted HTTP C2, plugin loading, file and process control, and secure deletion behavior. Fox-IT reports Namecheap-hosted C2 domains, host artifacts, sample hashes, and YARA rules, making the findings relevant for detecting low-footprint Lazarus observation campaigns that may precede data theft or financial operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| YARA | Lazarus_RemotePE_DPAPI_Encrypte… | 2026-05-22 | 2026-06-23 |
| YARA | Lazarus_RemotePE_class_strings | 2025-09-01 | 2026-06-23 |
| YARA | Lazarus_RemotePE_C2_strings | 2025-09-01 | 2026-06-23 |
| YARA | Lazarus_DPAPILoader_Hunting | 2025-09-01 | 2026-06-23 |
| HASH | 710f15302859c7af1c1e25219d70484… | 2026-05-22 | 2026-05-29 |
| HASH | 62e040a32aac2d2faa8d2bffa2cf7ab… | 2026-05-22 | 2026-05-29 |
| HASH | 6b33d20196267b0d64bca815ca86355… | 2026-05-22 | 2026-05-29 |
| HASH | 7a05188ab0129b0b4f38e2e7599c5c5… | 2025-09-01 | 2026-05-29 |
| HASH | 159471e1abc9adf6733af9d24781fbf… | 2025-09-01 | 2026-05-29 |
| HASH | 37f5afb9ed3761e73feb95daceb7a1f… | 2026-05-22 | 2026-05-22 |
| HASH | aa4a2d1215f864481994234f13ab485… | 2026-05-22 | 2026-05-22 |
| HASH | 4f6ae0110cf652264293df571d66955… | 2026-05-22 | 2026-05-22 |
| DOMAIN | devicelinkintel.com | 2026-05-22 | 2026-05-22 |
| DOMAIN | intelcloudinsights.com | 2026-05-22 | 2026-05-22 |
| DOMAIN | akamaicloud.com | 2026-05-22 | 2026-05-22 |
| DOMAIN | msdeliverycontent.com | 2026-05-22 | 2026-05-22 |
| DOMAIN | livedrivefiles.com | 2026-05-22 | 2026-05-22 |
| DOMAIN | aes-secure.net | 2025-09-01 | 2026-05-22 |
| DOMAIN | azureglobalaccelerator.com | 2025-09-01 | 2026-05-22 |