Fox-IT reported that a Lazarus-linked intrusion set targeted financial and cryptocurrency organizations with a stealthy three-stage malware chain built around DPAPILoader, RemotePELoader, and the memory-resident RemotePE RAT. The first stage decrypts a victim-bound payload using Windows DPAPI and XOR obfuscation, then establishes persistence through masqueraded services or DLL sideloading. The second stage prepares execution by using HellsGate/TartarusGate techniques to evade user-mode hooks and patching ETW telemetry before contacting command-and-control infrastructure for the final payload.
The final-stage RemotePE implant operates entirely in memory and supports file management, process control, command execution, configuration changes, sleep control, and plugin loading without writing itself to disk. Researchers said the toolset is engineered for stealth through environmental keying, low forensic footprint, and likely actor-operated payload delivery, and linked the activity to a North Korean Lazarus subgroup associated with AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces. Fox-IT also identified Namecheap-hosted infrastructure, active and historical domains, malware samples, host indicators, and YARA rules to aid detection and response.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-22, Fox-IT disclosed analysis of a three-stage Lazarus-linked malware chain—DPAPILoader, RemotePELoader, and the memory-only RemotePE RAT—used in an intrusion targeting financial and cryptocurrency organizations. The report linked the activity to a Lazarus subgroup associated with AppleJeus and shared C2 infrastructure, hashes, host indicators, and YARA rules.
In late February 2026, the attackers launched a third wave by redeploying a modified Deed RAT variant from C:\Recovery with updated configuration values and a new C2 domain, showing continued persistence and tooling evolution.
In a later wave during the same campaign, the attackers attempted to deploy Terndoor via a Mofu loader and a USOShared sideloading chain, including an attempted kernel driver service for vmflt.sys. Security controls reportedly blocked full execution of this stage.
Following initial access, the operators installed Deed RAT through a LogMeIn Hamachi-themed DLL sideloading chain and conducted lateral movement using RDP and SMB-based remote execution. The intrusion persisted despite remediation attempts, with repeated re-entry into the environment.
In late December 2025, attackers began a multi-wave intrusion against an Azerbaijani oil and gas company by exploiting an unpatched Microsoft Exchange server in ProxyNotShell-related activity and deploying a web shell.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourceblog.polyswarm.io
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourceblog.fox-it.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.