PULSE NAME
RemotePE: The Lazarus RAT that lives in memory
WHITE Lazarus AlienVault 2026-05-25 Modified: 2026-05-25
28
IOCs
MEDIUM VOLUME
A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
DPAPILoader RemotePELoader RemotePE ThemeForestRAT PondRAT POOLRAT
Indicators of Compromise (7 / 28 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 3b994549ab4fd9024b2f0155094d7aa43b70bb8f 2026-05-25
FileHash-SHA1 91def0a4dd9b35510d7f8897bc114f975a5d7e2b 2026-05-25
FileHash-SHA1 442f4abac74d844256e3ff60f929b358ded71881 2026-05-25
FileHash-SHA1 56f9b97fee195ed8dea39552eac288aa58cfaf48 2026-05-25
FileHash-SHA1 6c2b40c172a9c8706abc149ac72f5c509e4c5f56 2026-05-25
FileHash-SHA1 84bb3752307a088a6cdba4215aa9a993d34f353c 2026-05-25
FileHash-SHA1 bef8714787a76d33d74dc23e7c750e74b57f6f04 2026-05-25