← Back to Pulse Feed
PULSE DETAIL
A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services.
MITRE ATT&CK & Malware Families
Indicators of Compromise (8 / 28 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 159471e1abc9adf6733af9d24781fbf27a776b81d182901c2e04e28f3fe2e6f3 | — | 2026-05-25 | |
| FileHash-SHA256 | 37f5afb9ed3761e73feb95daceb7a1fdbb13c8b5fc1a2ba22e0ef7994c7920ef | — | 2026-05-25 | |
| FileHash-SHA256 | 4f6ae0110cf652264293df571d66955f7109e3424a070423b5e50edc3eb43874 | — | 2026-05-25 | |
| FileHash-SHA256 | 62e040a32aac2d2faa8d2bffa2cf7ab662228cebf9bb78eaa0a633c0b729d119 | — | 2026-05-25 | |
| FileHash-SHA256 | 6b33d20196267b0d64bca815ca863558d26b17cee77caf62a6cce8eae555ac8d | — | 2026-05-25 | |
| FileHash-SHA256 | 710f15302859c7af1c1e25219d704841b3fdbc48f16a5a574d5ab6cf4f4842e8 | — | 2026-05-25 | |
| FileHash-SHA256 | 7a05188ab0129b0b4f38e2e7599c5c52149ce0131140db33feb251d926428d68 | — | 2026-05-25 | |
| FileHash-SHA256 | aa4a2d1215f864481994234f13ab485b95150161b4566c180419d93dda7ac039 | — | 2026-05-25 |