North Korean hacker group Lazarus deploys fileless Trojan RemotePE, attacking cryptocurrency companies and banks

By: rootdata|2026/05/27 04:45:01
0
Share
copy

According to Cryptopolitan, cybersecurity analysts have discovered a new type of fileless remote access trojan (RAT) named RemotePE. It is believed that the cybercrime organization Lazarus Group, associated with North Korea, is using this trojan to attack banks and cryptocurrency companies. The trojan operates entirely in memory, making it difficult for traditional antivirus and forensic tools to detect. Attackers impersonate trading company employees via Telegram, using forged Calendly and Picktime links for social engineering attacks. The malware is loaded in a three-stage chain through DPAPILoader, RemotePELoader, and RemotePE, with the entire process avoiding contact with the file system, utilizing process hollowing, anti-analysis checks, and encrypted C2 communication to evade detection.

This malware was first discovered in September 2025. In the first four months of 2026, the Lazarus organization has stolen approximately $577 million in cryptocurrency assets, accounting for 76% of the total global cryptocurrency theft. Since 2017, the organization has accumulated a total theft amount of $6 billion.

-- Price

--

You may also like

Morning Report | Strategy sold 32 BTC and over 800,000 shares of MSTR last week; Binance officially announced its U.S. stock trading portal; Polymarket reached an exclusive partnership with OneFootball

Overview of Important Market Events on June 1st

Zhou Hang: How much is SpaceX really worth?

Great companies do not equal good stocks: A deep analysis of why SpaceX's $1.75 trillion IPO valuation may contain a $1.25 trillion bubble, and retail investors should avoid blindly chasing "story premiums."

IOSG: From Coinbase to Upbit: How a Token Completes a 28-Day Journey of Taking Over

The IOSG report indicates that by 2026, the listing of tokens on first-tier exchanges has formed a highly structured path where Coinbase and ByBit are responsible for initial discovery, Binance quickly verifies and confirms, and Korean exchanges provide liquidity at the end.

Exclusive Interview with Alpaca CEO: What is the background of the US stock underlying service provider behind Binance and Bitget?

Binance and Bitget's underlying service provider in the US stock market, Alpaca, has entered the unicorn club with its "AWS of Finance" model, currently holding 94% of the tokenized US stock market share and is accelerating the transformation of global on-chain financial infrastructure.

Variant: Three types of L1 assets are highly likely to become the main means of value storage

The basic judgment factors include: technical durability, resistance to censorship, scarcity, economic productivity, etc.

Does the performance on Perp DEX become an "invisible threshold" and "amplifier" for new coins to go live on CEX?

The liquidity migration of the new currency in 2026 from the perspective of open interest (OI) and asset labels.

Contents

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com