#RemotePE

Malware/Tool

2025-09-01 • Three Lazarus RATs coming for your cheese

RemotePE is a fully memory-resident Windows remote access trojan used by a Lazarus subgroup against high-value financial and cryptocurrency targets. Delivered through a multi-stage chain involving DPAPILoader and RemotePELoader, it executes without being written to disk and supports command execution, file and process operations, data collection and exfiltration, and reflective loading of additional plugins. RemotePE encrypts command-and-control traffic with AES-GCM, disguises communications as Microsoft telemetry, and can securely overwrite files before deletion, reducing forensic visibility and supporting long-term access to compromised systems.

Tagged Reports

« Back