PULSE NAME
RemotePE: The Lazarus RAT that lives in memory
WHITE Lazarus AlienVault 2026-05-25 Modified: 2026-05-25
28
IOCs
MEDIUM VOLUME
A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
DPAPILoader RemotePELoader RemotePE ThemeForestRAT PondRAT POOLRAT
Indicators of Compromise (2 / 28 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 23c2569a65870a9e412d98d5b3bdc554 2026-05-25
FileHash-MD5 75a46b23825ce7aa4ca297d93450f4e2 2026-05-25