← Back to Pulse Feed
PULSE DETAIL
A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services.
MITRE ATT&CK & Malware Families
Indicators of Compromise (7 / 28 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | 3b994549ab4fd9024b2f0155094d7aa43b70bb8f | — | 2026-05-25 | |
| FileHash-SHA1 | 91def0a4dd9b35510d7f8897bc114f975a5d7e2b | — | 2026-05-25 | |
| FileHash-SHA1 | 442f4abac74d844256e3ff60f929b358ded71881 | — | 2026-05-25 | |
| FileHash-SHA1 | 56f9b97fee195ed8dea39552eac288aa58cfaf48 | — | 2026-05-25 | |
| FileHash-SHA1 | 6c2b40c172a9c8706abc149ac72f5c509e4c5f56 | — | 2026-05-25 | |
| FileHash-SHA1 | 84bb3752307a088a6cdba4215aa9a993d34f353c | — | 2026-05-25 | |
| FileHash-SHA1 | bef8714787a76d33d74dc23e7c750e74b57f6f04 | — | 2026-05-25 |