Skip to content
Lazarus Deploys RemotePE Memory

Lazarus Deploys RemotePE Memory

Thehackernews [email protected] (The Hacker News) May 25, 2026

Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations.

RemotePE, per NCC Group subsidiary Fox-IT, is part of a multi-stage attack chain that involves two loaders tracked as DPAPILoader and RemotePELoader.

"DPAPILoader decrypts and

Extracted Entities

APT Groups (1)

Attack Types (1)

Countries (1)

Industries (1)

Malware (1)