RemotePE is a C++ remote access trojan for Windows associated with a North Korea-linked Lazarus subgroup whose activity overlaps AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces. It has been deployed against financial and cryptocurrency organizations, including a decentralized finance organization, and has replaced earlier PondRAT and ThemeForestRAT implants during intrusions. RemotePE executes entirely in memory without writing its own executable payload to disk.
The deployment chain comprises DPAPILoader, RemotePELoader, and RemotePE. DPAPILoader uses Windows Data Protection API encryption bound to the victim environment to decrypt and load RemotePELoader. RemotePELoader contacts command-and-control infrastructure, receives the final payload, and reflectively loads it into memory. Persistence is supplied by the first-stage loader through Windows service infrastructure. The chain incorporates direct-syscall techniques, removal of endpoint-security hooks, and suppression of Event Tracing for Windows; some RemotePE versions implement syscall resolution and telemetry suppression themselves. Associated intrusions have used targeted Telegram social engineering, impersonation of trading-company employees, and counterfeit meeting-scheduling websites.
RemotePE supports command execution, file operations, process creation and termination, configuration updates, sleep scheduling, data compression and exfiltration, and dynamic loading of reflective DLL plugins. Separate threads handle command-and-control communications and operator instructions. Its communications use AES-GCM encryption and compressed command-response data. Secure deletion routines overwrite files seven times before renaming and deleting them. These capabilities, combined with memory-resident execution and victim-bound loader encryption, reduce forensic visibility and support sustained remote control of compromised systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“We observed the actor cleaning up PondRAT and ThemeForestRAT, to deploy a more advanced RAT, which we named RemotePE.”
Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Once deployed, the RemotePE malware enables command execution, file manipulation, process management and data access...
IConsole ... Function ID 2 Execute a command and return its output
The first is HellsGate (specifically the TartarusGate variant), a technique that dynamically resolves Windows syscall numbers at runtime.
`decrypt_c2_message` decodes a base64 blob, derives a key and nonce, and uses `AES.new(key, AES.MODE_GCM, nonce)` to decrypt the ciphertext from the `C2Message` structure.
network packets utilize HTTP cookie names that mimic the Microsoft ecosystem. For instance, headers incorporate fields like MSCC and MicrosoftApplicationsTelemetryDeviceId to appear authentic.
Before contacting its command-and-control server, it removes security hooks placed by endpoint protection products and disables Windows event tracing, allowing the malware to operate with little or no visibility to defenders.
RemotePE also implements secure file deletion functionality by repeatedly overwriting files seven times prior to deletion, behavior previously associated with Lazarus-linked malware families such as PondRAT and POOLRAT.
On the first run it sleeps until the configured wake-up timestamp and on subsequent iterations it sleeps for a random interval within the configured bounds.
The final component, a fully featured remote access trojan (RAT), is executed entirely in memory and provides attackers with extensive control over compromised systems.
The attack followed a pattern increasingly common in Lazarus operations, social engineering via Telegram, with operatives posing as employees of a legitimate trading firm, scheduling fake meetings through spoofed Calendly and Picktime domains to gain initial access to a victim’s device.
Once deployed, the RemotePE malware enables command execution, file manipulation, process management and data access...
The script defines a `CabinetStream` structure with `compressed_buf` and uses `decompress_mszip` with zlib to decompress the command output after decryption.
It then initiates an encrypted HTTP communication loop with remote servers.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Memory-only remote access trojan executed entirely in memory that enables command execution, file manipulation, process management, and data access for long-term access, theft, intelligence collection, or exfiltration.
A memory-only remote access trojan/backdoor that runs entirely in RAM, handles outbound C2 and operator commands, securely deletes files, and supports runtime plugin DLL registration.
A fully memory-resident remote access trojan with encrypted C2, multithreaded command handling, file and process operations, command execution, configuration management, plugin/DLL loading, compression and exfiltration, and secure file deletion. It is designed for long-term stealthy access in financial and cryptocurrency environments.
RemotePE is a remote access trojan designed to operate entirely in memory for stealthy, long-term access. It is delivered through a multi-stage chain, communicates with a C2 server, supports file and process operations, uses evasion techniques such as Hell's Gate and ETW patching, and includes secure file deletion behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.