Lazarus and these guys figured out how to manipulate Telegram and fake calendar links, running Trojans in memory leaves no trace at all.

View Original
MarsBitNews
North Korean hacker group Lazarus deploys fileless Trojan RemotePE, attacking encryption companies and banks
Mars Finance News: According to Cryptopolitan, cybersecurity analysts have discovered a new fileless remote access Trojan (RAT) called RemotePE. It is believed that the Lazarus Group, a cybercriminal organization linked to North Korea, is using this Trojan to attack banks and cryptocurrency companies. The Trojan runs entirely in memory, making it difficult for traditional antivirus and forensic tools to detect. Attackers impersonate employees of trading companies via Telegram and use forged Calendly and Picktime links to carry out social engineering attacks. The malware is loaded in a chained sequence of three stages—DPAPILoader, RemotePELoader, and RemotePE—through which the entire process avoids touching the file system, using process hollowing, anti-analysis checks, and encrypted C2 communication to evade detection. The malicious
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned