North Korean hacker group Lazarus deploys fileless Trojan RemotePE, attacking cryptocurrency companies and banks
According to Cryptopolitan, cybersecurity analysts have discovered a new type of fileless remote access trojan (RAT) named RemotePE. It is believed that the cybercrime organization Lazarus Group, associated with North Korea, is using this trojan to attack banks and cryptocurrency companies. The trojan operates entirely in memory, making it difficult for traditional antivirus and forensic tools to detect. Attackers impersonate trading company employees via Telegram, using forged Calendly and Picktime links for social engineering attacks. The malware is loaded in a three-stage chain through DPAPILoader, RemotePELoader, and RemotePE, with the entire process avoiding contact with the file system, utilizing process hollowing, anti-analysis checks, and encrypted C2 communication to evade detection.
This malware was first discovered in September 2025. In the first four months of 2026, the Lazarus organization has stolen approximately $577 million in cryptocurrency assets, accounting for 76% of the total global cryptocurrency theft. Since 2017, the organization has accumulated a total theft amount of $6 billion.
You may also like

Three years later: Looking back at my judgment of ChatGPT in 2023

From Casino Tools to Global Pricing Machines: The NYSE Leader's Perspective on Hyperliquid

A Detailed Analysis of "Stock God Serenity" Investment Methodology

Sharplink CEO: The future of Ethereum is unfolding

Morning Report | Korea Investment & Securities and OKX plan to jointly acquire 40% of Coinone; Polymarket denies implementing KYC comprehensively; Grayscale delays U.S. stock IPO plans

Bit Digital CEO: Why I Bought More ETH

A Decade of Three Waves of Stock Tokenization from Bitget's Reality: An Unfinished Financial Exploration

"Hu Run Baifu" Dialogue with Sun Yuchen: A New Paradigm of Value Circulation in the Web3 Transformation Cycle

Is it hackers and regulation that ruined DeFi?

Chris Lee: From crypto OG to heavy investments in the three storage giants, predictions on AI bull market corrections, Web4, and opportunities for the younger generation

Ready for a Walk on the Wilder Side of Proof of Talk 2026? Join WEEX Labs in Paris

Gold vs Bitcoin in 2026: Which Market Is Giving Traders Better Opportunities?

Morning News | Coinbase partners with Standard Chartered Bank to expand multi-currency fiat channels; Sharplink and Forward will be included in the Russell Index; JPMorgan may issue stablecoins in the future

Hash Global Founder: Why I Also Chose to Liquidate All My ETH?

Tokenized US Stock Duel: Ondo vs. xStocks, Who is Defining On-Chain Nasdaq?

He Yideng ranked: Since you're here, you might as well

The era of regulatory arbitrage has come to an end, and the value of cryptocurrency exchange licenses is being fiercely contested

