External Publication
Visit Post

Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

The Hacker News | #1 Trusted Source for Cybersecurity News [Uno… May 25, 2026
Source
Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations. RemotePE, per NCC Group subsidiary Fox-IT, is part of a multi-stage attack chain that involves two loaders tracked as DPAPILoader and RemotePELoader. "DPAPILoader decrypts and

Discussion in the ATmosphere

Loading comments...