RunPE is a process-injection utility commonly used to execute an embedded payload within a legitimate Windows process. Observed implementations create a target process in a suspended state and use process hollowing to replace its memory image with the payload before resuming execution. It has been used as an in-memory component in malware delivery chains to inject payloads including AsyncRAT, AZORult, and QDoor, frequently to reduce the payload's on-disk footprint and blend execution with legitimate processes. RunPE components have appeared in script-driven loader chains and alongside DLL sideloading or registration-based execution; it has also been identified as an open-source tool in some incidents. RunPE is an injector rather than a standalone malware family, and its ultimate functionality depends on the injected payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Codecaudiog A campaign in June 2025 used a PowerShell → RunPE → PULSAR infection sequence.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader/process-execution component used in the Codecaudiog A infection chain to deliver PULSAR RAT.
A .NET process-injection utility used as an intermediate stage to hollow a legitimate process and inject the AsyncRAT payload directly from memory.
A loader program previously sold by the BlackGuard operator before marketing BlackGuard.
Binary loader and process injector used to load AZORult, Remcos, and DarkVNC payloads into legitimate processes such as notepad.exe, explorer.exe, and control.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.