Security News

Cybersecurity news aggregator

🕵️
HIGH Vulnerabilities Malpedia

RemotePE: The Lazarus RAT that lives in memory

The article details RemotePE, a fileless Remote Access Trojan (RAT) deployed by the Lazarus group that resides solely in memory to evade detection. It leverages a loader component called `win.dpapi_loader` to decrypt and execute the final payload without writing it to disk. The summary does not provide information on a specific software vulnerability, CVSS score, affected versions, a fixed version, or a workaround.
Read Full Article →

2026-05-22 (Back to Inventory) RemotePE: The Lazarus RAT that lives in memory Author(s): Mick Koomen , Yun Zheng Hu Organization: Fox-IT win.dpapi_loader win.remotepe Open article directly Open article on Archive.org Related Articles 2025-09-01 ⋅ Fox-IT ⋅ Mick Koomen , Yun Zheng Hu Three Lazarus RATs coming for your cheese SimpleTea POOLRAT ThemeForestRAT 2024-03-28 ⋅ Fox-IT ⋅ Joshua Kamp Android Malware Vultur Expands Its Wingspan Brunhilda Vultur 2023-11-01 ⋅ nccgroup ⋅ Mick Koomen Popping Blisters for research: An overview of past payloads and exploring recent developments Blister Cobalt Strike

Share this article