North Korean hacker group Lazarus deploys fileless Trojan RemotePE, attacking cryptocurrency companies and banks
According to Cryptopolitan, cybersecurity analysts have discovered a new type of fileless remote access trojan (RAT) named RemotePE. It is believed that the cybercrime organization Lazarus Group, associated with North Korea, is using this trojan to attack banks and cryptocurrency companies. The trojan operates entirely in memory, making it difficult for traditional antivirus and forensic tools to detect. Attackers impersonate trading company employees via Telegram, using forged Calendly and Picktime links for social engineering attacks. The malware is loaded in a three-stage chain through DPAPILoader, RemotePELoader, and RemotePE, with the entire process avoiding contact with the file system, utilizing process hollowing, anti-analysis checks, and encrypted C2 communication to evade detection.
This malware was first discovered in September 2025. In the first four months of 2026, the Lazarus organization has stolen approximately $577 million in cryptocurrency assets, accounting for 76% of the total global cryptocurrency theft. Since 2017, the organization has accumulated a total theft amount of $6 billion.
You may also like

Morning Report | Strategy sold 32 BTC and over 800,000 shares of MSTR last week; Binance officially announced its U.S. stock trading portal; Polymarket reached an exclusive partnership with OneFootball

Zhou Hang: How much is SpaceX really worth?

IOSG: From Coinbase to Upbit: How a Token Completes a 28-Day Journey of Taking Over

Exclusive Interview with Alpaca CEO: What is the background of the US stock underlying service provider behind Binance and Bitget?

Variant: Three types of L1 assets are highly likely to become the main means of value storage

Does the performance on Perp DEX become an "invisible threshold" and "amplifier" for new coins to go live on CEX?

a16z Crypto's latest article: Why do we need to predict the market?

Strategy cashes out 2.5 million USD, but Bitcoin's market value dropped by 80 billion USD in one day

Collective Change of Ownership for Crypto Exchanges? The Positioning Competition Among South Korean Financial Giants

WEEXPERIENCE Trading Bootcamp in Poland: How WEEX & FireCrew Are Making Crypto Trading Accessible to Everyone

Paris Reigns Supreme: How PSG Crushed Arsenal’s Dream in a Historic UCL Final Thriller

Full text and analysis of the speech by the CEO of SanDisk at the 42nd Annual Strategic Decision Conference of Bernstein

TaiJi completes $3.5 million strategic financing, with investments from Castrum Capital, Becker Ventures, and Coinvestor Ventures

Bitcoin Stuck Near $73K? How Traders Are Finding Rewards in a Sideways June Market

What Is a Bitcoin ETF? A Simple Guide for 2026

Best AI Crypto Coins 2026: Top 7 Tokens Ranked by Data

How to Stake Solana: A Step-by-Step Guide for 2026






