ThemeForestRAT is a remote access trojan associated with Lazarus Group / North Korean APT activity. Fox-IT identified it as one of three Lazarus-deployed RATs discussed alongside PondRAT and RemotePE, and incident response investigations found that operators had replaced older ThemeForestRAT and PondRAT implants with a more advanced memory-only framework composed of DPAPILoader, RemotePELoader, and RemotePE. The reporting links this broader activity to clusters tracked as AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces, and to campaigns targeting financial and cryptocurrency organizations, including decentralized finance entities. High-confidence details in the provided content about ThemeForestRAT itself are limited; the content does not describe its internal functionality, infection chain, or specific IOCs in detail. However, it is explicitly characterized as older Lazarus tooling that preceded the newer RemotePE toolset, and the related infrastructure and operations were associated with long-duration access objectives and financially motivated follow-on activity such as cryptocurrency theft, financial fraud, and data exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers identified the malware during incident response investigations where older Lazarus tooling, including ThemeForestRAT and PondRAT, had been replaced with a significantly more advanced memory-only framework.
In one investigation, we observed that the actor had replaced ThemeForestRAT and PondRAT with a more sophisticated memory-only toolset.
Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An older implant previously used by the threat actors before transitioning to the newer memory-only Lazarus toolset.
An older Lazarus-associated RAT/tooling family referenced as having been replaced by the newer RemotePE framework in observed intrusions.
A previously used Lazarus remote access trojan that was reportedly replaced by the newer RemotePE toolset in at least one investigation.
A previously used RAT in earlier campaigns by the same Lazarus subgroup, later replaced by the DPAPILoader/RemotePELoader/RemotePE memory-only toolset.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.