hackspace
165 subscribers
283 photos
82 videos
25 files
1.02K links
hackspace
Download Telegram
😁2
😏
Fox-IT (NCC Group) details RemotePE, a North-Korean Lazarus in-memory RAT delivered through a three-stage chain — DPAPILoader (environmentally-keyed first-stage), RemotePELoader (HellsGate / ETW-patched HTTP beacon) and RemotePE itself, which never touches disk. The writeup walks AES-GCM C2, MSZIP-compressed command batches, the IConsole / IFileExplorer / IProcess command surface, infrastructure, MITRE ATT&CK mapping, and a full IOC set spanning July 2023 — May 2026.


https://core-jmp.org/2026/05/remotepe-lazarus-in-memory-rat-dpapi-loader-chain/