Threat reportMalwareTL-2026-0722
RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage Chain
RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader (TL-2026-0722), also tracked as RemotePE, is a high-severity malware campaign, first published 2026-06-09. It is attributed to Lazarus Group (North Korea) with high confidence, affects Microsoft Windows, maps to 37 MITRE ATT&CK techniques (T1003.001, T1005, T1027), and is covered by 9 detection rules and 31 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 37MITRE ATT&CK
- Actors
- 1Lazarus Group
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 31Indicators of compromise
Key facts for TL-2026-0722
- Threat ID
- TL-2026-0722
- Also known as
- RemotePE, win.remotepe, DPAPI Loader, win.dpapi_loader, RemotePELoader
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Lazarus Group
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- financial, cryptocurrency, decentralized-finance, trading, investment
- Target regions
- Global, North America, Europe, Asia
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader
Malware and tooling: DPAPI Loader, RemotePE, SimpleTea (ELF), ThemeForestRAT, FRPC / MidProxy / Proxy Mini, Mimikatz
How RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader works
RemotePE is a sophisticated multithreaded C++ remote access trojan attributed to North Korea's Lazarus Group, executed entirely in system memory with no filesystem artifacts. It is delivered through a three-stage chain (DPAPILoader -> RemotePELoader -> RemotePE) that leverages DPAPI environmental keying and aggressive EDR evasion, and is reserved for high-value financial and cryptocurrency targets.
RemotePE is the apex payload of a memory-only toolset that Fox-IT (Mick Koomen, Yun Zheng Hu) attributes to a financially-motivated subgroup of the North Korean Lazarus Group (overlapping with AppleJeus / Citrine Sleet / Gleaming Pisces / UNC4736). The actor replaced its older PondRAT and ThemeForestRAT tooling with a purpose-built, low-forensic-footprint chain designed for long-term covert observation of decentralized-finance (DeFi), trading, and cryptocurrency organizations before high-impact financial theft.
The intrusion typically begins with highly tailored social engineering over Telegram, where operators impersonate employees of a trading firm and schedule meetings using fraudulent Calendly- and Picktime-themed scheduling domains to deliver an initial payload (a then-zero-day Chrome exploit is suspected for some intrusions). Early footholds use PerfhLoader to drop PondRAT (a stripped-down POOLRAT/SIMPLESEA variant) and load ThemeForestRAT directly into memory; supporting tools include a Chrome cookie/credential stealer, a keylogger and screenshot utility, Mimikatz, and FRPC/MidProxy/Proxy Mini tunnelers. After roughly three months of access, the operators clean up and deploy the more sophisticated RemotePE chain against the highest-value hosts.
Stage 1, DPAPILoader, is a DLL (observed as Iassvc.dll, sspicli.dll, wmiclnt.dll) masquerading as the Windows Internet Authentication Service. It scans C:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US*.* for Microsoft Cabinet files (magic 4D 53 43 46), then decrypts the next stage using Windows DPAPI plus an XOR (0x8D) layer and reflectively loads it via libpeconv. Because DPAPI keys are unique per victim, the encrypted blobs cannot be analyzed off-host (e.g., on VirusTotal) without the victim's keys -- an environmental-keying defense against sandboxing. Persistence is via a malicious service DLL under svchost.exe or DLL sideloading.
Stage 2, RemotePELoader, is a C2 beacon. It resolves syscalls with HellsGate/TartarusGate (NtOpenSection, NtMapViewOfSection, NtUnmapViewOfSection, NtProtectVirtualMemory, NtClose), remaps DLLs from \KnownDlls to unhook EDR, and patches ETW by overwriting EtwEventWrite with 'XOR RAX,RAX; RET'. Its small (<20 KiB) DPAPI-encrypted config holds up to three C2 URLs, proxy settings, user-agent strings, and sleep/reconnect timers. C2 is HTTP POST over TLS with cookie-based authentication (fields including MSCC, MicrosoftApplicationsTelemetryDeviceId carrying the bot ID, MSFPC, HASH, LV, V, LU, at_check/ai_session) and AES-GCM payload encryption keyed by a SplitMix64-seeded Mersenne Twister PRNG; each message is uint64 seed + 16-byte auth tag + ciphertext.
Stage 3, RemotePE, is a multithreaded, object-oriented C++ RAT run only in memory. An IChannelController thread handles C2 while an IMiddleController thread executes commands, with an external named-event trigger (GUID 554D5C1F-AABE-49E4-AB57-994D22ECED28) for out-of-band activation. RTTI-based command classes provide configuration control (IConfigProfile), console/command execution and module management (IConsole), file/drive enumeration with secure 7-pass overwrite deletion and ZIP archival (IFileExplorer), process management (IProcess), sleep/exit scheduling (ITimer), and a no-op ping (IPing). It supports a plugin system of dual-format 'shellcodified DLLs' and compresses output with MSZIP via cabinet.dll. Delivery is actor-in-the-loop: operators manually push the payload, and observed delivery windows cluster in UTC+9 (KST) daytime, reinforcing the DPRK attribution. C2 infrastructure is hosted on Namecheap shared hosting, defeating naive IP-based blocking.
MITRE ATT&CK techniques used in TL-2026-0722
Credential Access
T1003.001 LSASS Memory; T1056.001 Keylogging; T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers
Collection
T1005 Data from Local System; T1113 Screen Capture; T1560.001 Archive via Utility
Defense Evasion
T1027 Obfuscated Files or Information; T1036.004 Masquerade Task or Service; T1055 Process Injection; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1480.001 Environmental Keying; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Command and Control
T1071.001 Web Protocols; T1090 Proxy; T1105 Ingress Tool Transfer; T1132.001 Standard Encoding; T1573.001 Symmetric Cryptography; T1573.002 Asymmetric Cryptography
Execution
T1106 Native API; T1129 Shared Modules; T1204 User Execution
Initial Access
T1189 Drive-by Compromise; T1566 Phishing; T1566.003 Spearphishing via Service
Persistence
stealth
Resource Development
T1583 Acquire Infrastructure; T1583.003 Virtual Private Server; T1587.001 Malware
Impact
defense-impairment
Affected products and versions in RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader
- Microsoft — Windows
Vulnerable versions: Windows 10; Windows 11; Windows Server
Remediation for RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader
Immediate actions
- Block and alert on the known RemotePE C2 domains (livedrivefiles.com, aes-secure.net, azureglobalaccelerator.com, msdeliverycontent.com, akamaicloud.com, intelcloudinsights.com, devicelinkintel.com) at DNS/proxy/perimeter
- Hunt for DPAPI-encrypted blobs and Cabinet files in C:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US*.*
- Hunt for service or sideloaded DLLs named Iassvc.dll, sspicli.dll, wmiclnt.dll running from non-standard paths
- Search for the named event 554D5C1F-AABE-49E4-AB57-994D22ECED28 and processes opening it
Workarounds
- Disable unnecessary DLL sideloading paths and enforce service DLL signing
- Apply phishing-resistant MFA and review browser cookie/credential exposure on potentially compromised hosts
Longer-term hardening
- Deploy EDR with in-memory/behavioral detection (reflective loading, ETW patching, KnownDlls remapping, HellsGate syscalls) since the RAT writes nothing to disk
- Monitor for EtwEventWrite tampering and direct/indirect syscall usage
- Restrict and monitor Telegram and third-party scheduling-link usage for finance/crypto staff; enforce application allowlisting
- Inspect TLS metadata (SNI, cookie fields MicrosoftApplicationsTelemetryDeviceId/MSFPC/ai_session and JSON key armAuthorization) where lawful
Weaknesses (CWE) in RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader
Timeline of RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader
- Earliest RemotePE compilation timestamp observed (sample 37f5afb9...), marking the start of RemotePE development.
- First RemotePE C2 domain livedrivefiles.com first observed/registered.
- Multiple C2 domains (aes-secure.net, azureglobalaccelerator.com) first observed, expanding the infrastructure.
- Standalone (non-DPAPI config) RemotePE variant observed (sample 6b33d201...).
- Earliest DPAPILoader artifact observed (Iassvc.dll, sample 4f6ae011...) masquerading as Internet Authentication Service.
- Infrastructure expansion with C2 domains msdeliverycontent.com and akamaicloud.com.
- DPAPILoader variant sspicli.dll deployed via DLL sideloading (sample 159471e1...).
- RemotePE variant reverted to disk-based DPAPI config (sample 62e040a3...).
- Final RemotePE variant using thread-parameter config delivery (sample 710f1530...).
- New C2 domain devicelinkintel.com first observed.
- DPAPILoader variant wmiclnt.dll with embedded payload observed (sample aa4a2d12...).
- C2 domain livedrivefiles.com last observed active.
- Fox-IT (Mick Koomen, Yun Zheng Hu) publishes the RemotePE analysis; indexed on Malpedia.
Sources cited for RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader
- RemotePE: The Lazarus RAT that lives in memory (Fox-IT / Mick Koomen, Yun Zheng Hu)
- RemotePE on Malpedia (Fraunhofer FKIE)
- Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms
- Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE
- Lazarus, DPAPI, and the art of leaving nothing behind in RemotePE (Andrea Fortuna)
- Active Exploitation Alert: Lazarus Group Targets Financial and Crypto Firms with RemotePE Memory-Only RAT (Rescana)
- Lazarus Expands Financial Espionage Operations With Memory-Resident RemotePE RAT (PolySwarm)
Detection coverage for TL-2026-0722
As of 2026-06-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0722 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.