Adversary Intelligence — 2026-05-25
Fox-IT Exposes Lazarus Groups Memory-Only RemotePE RAT Targeting Financial and Crypto Organizations
BLUFEnvironmental keying paired with in-memory execution and userland EDR blinding gives this Lazarus subgroup a tradecraft edge that will frustrate post-incident attribution and prolong dwell time in crypto and financial targets.
Fox-IT researchers Yun Zheng Hu and Mick Koomen on May 22 published a technical breakdown of a three-stage, memory-only toolset deployed by a Lazarus subgroup, linked to Citrine Sleet and UNC4736, against financial and cryptocurrency organizations 12. DPAPILoader, the first stage, masquerades as Windows' Internet Authentication Service and applies DPAPI-based environmental keying, binding each payload cryptographically to the victim host and, as Fox-IT notes, rendering off-system analysis infeasible without the victim's OS credentials 12. RemotePELoader disables userland EDR hooks via Hell's Gate syscall unhooking and neutralizes ETW telemetry before retrieving RemotePE from an operator-controlled C2 server; RemotePE then executes entirely in memory and writes nothing to disk 13. Fox-IT obtained four RemotePE samples with compilation timestamps spanning July 2023 to mid-2024 and confirmed neither RemotePELoader nor RemotePE appeared on VirusTotal before the May 22 publication 13.
Analysis
Based on Fox-IT's original research with no independent corroboration, DPAPI environmental keying is the crux: any captured payload is forensically inert without the victim's OS credentials, collapsing the reverse-engineering workflow that enables rapid threat characterization. Zero VirusTotal presence before May 22 and actor-in-the-loop delivery confirm deliberate reservation for high-value targets, with four samples spanning July 2023 to mid-2024 marking roughly one year of development. Hell's Gate unhooking and ETW patching systematically blind userland EDR, raising the likelihood of undetected long-dwell intrusions in financial and crypto environments lacking kernel-level telemetry. The restricted distribution may indicate Lazarus holds pre-positioned accesses well beyond current incident response visibility.
4 sources
- RemotePE: The Lazarus RAT that lives in memory - Fox-IT
- RemotePE: The Lazarus RAT that lives in memory - Malware News
- Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms - The Hacker News
- Lazarus Deploys RemotePE Memory-Only RAT for Financial and Crypto Companies - Fyself News
View in full brief →