RemotePE: The Lazarus RAT that lives in memory

Reported 25 May 2026 by otx · Severity: medium

A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePE