Threat reportMalwareTL-2026-0722

RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage Chain

highACTIVE

RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader (TL-2026-0722), also tracked as RemotePE, is a high-severity malware campaign, first published 2026-06-09. It is attributed to Lazarus Group (North Korea) with high confidence, affects Microsoft Windows, maps to 37 MITRE ATT&CK techniques (T1003.001, T1005, T1027), and is covered by 9 detection rules and 31 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
37MITRE ATT&CK
Actors
1Lazarus Group
Detection rules
9SPL · KQL · Sigma
IOCs
31Indicators of compromise

Key facts for TL-2026-0722

Threat ID
TL-2026-0722
Also known as
RemotePE, win.remotepe, DPAPI Loader, win.dpapi_loader, RemotePELoader
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Lazarus Group
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
financial, cryptocurrency, decentralized-finance, trading, investment
Target regions
Global, North America, Europe, Asia
Detection rules
9
Indicators of compromise
31

Malware and tooling in RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader

Malware and tooling: DPAPI Loader, RemotePE, SimpleTea (ELF), ThemeForestRAT, FRPC / MidProxy / Proxy Mini, Mimikatz

How RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader works

RemotePE is a sophisticated multithreaded C++ remote access trojan attributed to North Korea's Lazarus Group, executed entirely in system memory with no filesystem artifacts. It is delivered through a three-stage chain (DPAPILoader -> RemotePELoader -> RemotePE) that leverages DPAPI environmental keying and aggressive EDR evasion, and is reserved for high-value financial and cryptocurrency targets.

RemotePE is the apex payload of a memory-only toolset that Fox-IT (Mick Koomen, Yun Zheng Hu) attributes to a financially-motivated subgroup of the North Korean Lazarus Group (overlapping with AppleJeus / Citrine Sleet / Gleaming Pisces / UNC4736). The actor replaced its older PondRAT and ThemeForestRAT tooling with a purpose-built, low-forensic-footprint chain designed for long-term covert observation of decentralized-finance (DeFi), trading, and cryptocurrency organizations before high-impact financial theft.

The intrusion typically begins with highly tailored social engineering over Telegram, where operators impersonate employees of a trading firm and schedule meetings using fraudulent Calendly- and Picktime-themed scheduling domains to deliver an initial payload (a then-zero-day Chrome exploit is suspected for some intrusions). Early footholds use PerfhLoader to drop PondRAT (a stripped-down POOLRAT/SIMPLESEA variant) and load ThemeForestRAT directly into memory; supporting tools include a Chrome cookie/credential stealer, a keylogger and screenshot utility, Mimikatz, and FRPC/MidProxy/Proxy Mini tunnelers. After roughly three months of access, the operators clean up and deploy the more sophisticated RemotePE chain against the highest-value hosts.

Stage 1, DPAPILoader, is a DLL (observed as Iassvc.dll, sspicli.dll, wmiclnt.dll) masquerading as the Windows Internet Authentication Service. It scans C:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US*.* for Microsoft Cabinet files (magic 4D 53 43 46), then decrypts the next stage using Windows DPAPI plus an XOR (0x8D) layer and reflectively loads it via libpeconv. Because DPAPI keys are unique per victim, the encrypted blobs cannot be analyzed off-host (e.g., on VirusTotal) without the victim's keys -- an environmental-keying defense against sandboxing. Persistence is via a malicious service DLL under svchost.exe or DLL sideloading.

Stage 2, RemotePELoader, is a C2 beacon. It resolves syscalls with HellsGate/TartarusGate (NtOpenSection, NtMapViewOfSection, NtUnmapViewOfSection, NtProtectVirtualMemory, NtClose), remaps DLLs from \KnownDlls to unhook EDR, and patches ETW by overwriting EtwEventWrite with 'XOR RAX,RAX; RET'. Its small (<20 KiB) DPAPI-encrypted config holds up to three C2 URLs, proxy settings, user-agent strings, and sleep/reconnect timers. C2 is HTTP POST over TLS with cookie-based authentication (fields including MSCC, MicrosoftApplicationsTelemetryDeviceId carrying the bot ID, MSFPC, HASH, LV, V, LU, at_check/ai_session) and AES-GCM payload encryption keyed by a SplitMix64-seeded Mersenne Twister PRNG; each message is uint64 seed + 16-byte auth tag + ciphertext.

Stage 3, RemotePE, is a multithreaded, object-oriented C++ RAT run only in memory. An IChannelController thread handles C2 while an IMiddleController thread executes commands, with an external named-event trigger (GUID 554D5C1F-AABE-49E4-AB57-994D22ECED28) for out-of-band activation. RTTI-based command classes provide configuration control (IConfigProfile), console/command execution and module management (IConsole), file/drive enumeration with secure 7-pass overwrite deletion and ZIP archival (IFileExplorer), process management (IProcess), sleep/exit scheduling (ITimer), and a no-op ping (IPing). It supports a plugin system of dual-format 'shellcodified DLLs' and compresses output with MSZIP via cabinet.dll. Delivery is actor-in-the-loop: operators manually push the payload, and observed delivery windows cluster in UTC+9 (KST) daytime, reinforcing the DPRK attribution. C2 infrastructure is hosted on Namecheap shared hosting, defeating naive IP-based blocking.

MITRE ATT&CK techniques used in TL-2026-0722

Credential Access

T1003.001 LSASS Memory; T1056.001 Keylogging; T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers

Collection

T1005 Data from Local System; T1113 Screen Capture; T1560.001 Archive via Utility

Defense Evasion

T1027 Obfuscated Files or Information; T1036.004 Masquerade Task or Service; T1055 Process Injection; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1480.001 Environmental Keying; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

Command and Control

T1071.001 Web Protocols; T1090 Proxy; T1105 Ingress Tool Transfer; T1132.001 Standard Encoding; T1573.001 Symmetric Cryptography; T1573.002 Asymmetric Cryptography

Execution

T1106 Native API; T1129 Shared Modules; T1204 User Execution

Initial Access

T1189 Drive-by Compromise; T1566 Phishing; T1566.003 Spearphishing via Service

Persistence

T1543.003 Windows Service

stealth

T1574.001 DLL

Resource Development

T1583 Acquire Infrastructure; T1583.003 Virtual Private Server; T1587.001 Malware

Impact

T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader

  • Microsoft — Windows
    Vulnerable versions: Windows 10; Windows 11; Windows Server

Remediation for RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader

Immediate actions

  • Block and alert on the known RemotePE C2 domains (livedrivefiles.com, aes-secure.net, azureglobalaccelerator.com, msdeliverycontent.com, akamaicloud.com, intelcloudinsights.com, devicelinkintel.com) at DNS/proxy/perimeter
  • Hunt for DPAPI-encrypted blobs and Cabinet files in C:\ProgramData\Microsoft\Windows\DeviceMetadataStore\en-US*.*
  • Hunt for service or sideloaded DLLs named Iassvc.dll, sspicli.dll, wmiclnt.dll running from non-standard paths
  • Search for the named event 554D5C1F-AABE-49E4-AB57-994D22ECED28 and processes opening it

Workarounds

  • Disable unnecessary DLL sideloading paths and enforce service DLL signing
  • Apply phishing-resistant MFA and review browser cookie/credential exposure on potentially compromised hosts

Longer-term hardening

  • Deploy EDR with in-memory/behavioral detection (reflective loading, ETW patching, KnownDlls remapping, HellsGate syscalls) since the RAT writes nothing to disk
  • Monitor for EtwEventWrite tampering and direct/indirect syscall usage
  • Restrict and monitor Telegram and third-party scheduling-link usage for finance/crypto staff; enforce application allowlisting
  • Inspect TLS metadata (SNI, cookie fields MicrosoftApplicationsTelemetryDeviceId/MSFPC/ai_session and JSON key armAuthorization) where lawful

Weaknesses (CWE) in RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader

CWE-506, CWE-1188

Timeline of RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader

  • Earliest RemotePE compilation timestamp observed (sample 37f5afb9...), marking the start of RemotePE development.
  • First RemotePE C2 domain livedrivefiles.com first observed/registered.
  • Multiple C2 domains (aes-secure.net, azureglobalaccelerator.com) first observed, expanding the infrastructure.
  • Standalone (non-DPAPI config) RemotePE variant observed (sample 6b33d201...).
  • Earliest DPAPILoader artifact observed (Iassvc.dll, sample 4f6ae011...) masquerading as Internet Authentication Service.
  • Infrastructure expansion with C2 domains msdeliverycontent.com and akamaicloud.com.
  • DPAPILoader variant sspicli.dll deployed via DLL sideloading (sample 159471e1...).
  • RemotePE variant reverted to disk-based DPAPI config (sample 62e040a3...).
  • Final RemotePE variant using thread-parameter config delivery (sample 710f1530...).
  • New C2 domain devicelinkintel.com first observed.
  • DPAPILoader variant wmiclnt.dll with embedded payload observed (sample aa4a2d12...).
  • C2 domain livedrivefiles.com last observed active.
  • Fox-IT (Mick Koomen, Yun Zheng Hu) publishes the RemotePE analysis; indexed on Malpedia.

Sources cited for RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader

Detection coverage for TL-2026-0722

As of 2026-06-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0722 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
31 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats