Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms
Researchers say Lazarus used RemotePE, a memory-only RAT, in attacks against financial and crypto targets.
Intelligence analysis by GPT-5.4 Mini
Fox-IT says the North Korea-linked Lazarus Group used RemotePE in a staged intrusion chain with DPAPILoader and RemotePELoader. The malware runs in memory, evades detection, and appears built for stealthy, long-term access against high-value targets.
A security team found a sneaky computer spy tool called RemotePE. It can live in memory instead of leaving easy clues on the hard drive, like a thief who walks through a house without dropping footprints.
The report says a group linked to North Korea used this tool against money and crypto companies. First, one piece unlocks another piece, and then the final tool starts listening for orders from far away.
It matters because hiding tools are harder to catch. For defenders, it means ordinary checks may miss the intruder, so watching for strange behavior becomes much more important.
Analysis
What the report says
Fox-IT, a NCC Group subsidiary, says Lazarus Group has been using a cross-platform malware family called RemotePE against financial and cryptocurrency organizations. The infection chain is staged: a loader named DPAPILoader decrypts and loads another loader, RemotePELoader, which then reaches out to a command-and-control server and fetches the final payload.
The key detail is how the final stage behaves. RemotePE is executed entirely in memory and is never written to disk, which means fewer filesystem artifacts for defenders to recover. The researchers also say the loader uses techniques associated with evasion, including Hell's Gate and patching Event Tracing for Windows, to reduce detection.
Fox-IT says RemotePE supports several command categories. Those include changing configuration, working directories, DLL handling, file operations, process discovery and control, sleeping, exiting, and pinging the server. One deletion routine stands out because it overwrites files seven times before renaming and deleting them, a pattern also seen in PondRAT and POOLRAT. That is consistent with a toolkit designed to stay hidden while maintaining access.
Why the timeline matters
The samples Fox-IT recovered suggest active development from mid-2023 through mid-2024, with the earliest DPAPILoader artifact dating to November 2023 and the first RemotePE compilation timestamp set to July 4, 2023. The researchers say the low detection rate and the actor-in-the-loop delivery model suggest the malware is being reserved for high-value targets where long-term access matters more than speed.
In practical terms, the story is not just that Lazarus has another RAT. It is that the group appears to be investing in tooling that avoids obvious traces, especially for targets tied to money movement and digital assets. That raises the cost of detection and makes endpoint visibility, memory analysis, and behavioral monitoring more important.
Key points
- Fox-IT says Lazarus used RemotePE against financial and cryptocurrency targets.
- The attack chain uses DPAPILoader and RemotePELoader before the final RAT runs in memory.
- RemotePE never writes itself to disk, which leaves few filesystem traces.
- The malware can manage configuration, files, processes, DLLs, and command-and-control traffic.
- The researchers say the toolkit looks built for stealthy, long-term access.



