2026-05-26HIGHLazarus "RemotePE": a three-stage memory-only RAT that unhooks EDR and blinds ETW
RemotePE
tool · tool:remotepe
Lazarus three-stage memory-only RAT chain (DPAPILoader / RemotePELoader / RemotePE) with HellsGate and ETW patching.
Coverage
1
first 2026-05-26 → last 2026-05-26
Latest activity
2026-05-26
Lazarus "RemotePE": a three-stage memory-only RAT that unhooks EDR and blinds ETW
Peak priority
high
1 high
Targets
finance
sectors: finance · regions: europe
Sources cited
13
3 hosts
Defender insights
What each entry about RemotePE tells a defender to do, newest first.
Detection
Story timeline
Hunting pivots
ATT&CK techniques (15 across 7 tactics)
15 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessPhishing
- ExecutionCommand and Scripting Interpreter · Native API
- PersistenceCreate or Modify System Process · Create or Modify System Process: Windows Service
- Privilege EscalationProcess Injection · Process Injection: Portable Executable Injection · Create or Modify System Process · Create or Modify System Process: Windows Service
- StealthProcess Injection · Process Injection: Portable Executable Injection · Indicator Removal · Indicator Removal: File Deletion · Deobfuscate/Decode Files or Information · Execution Guardrails · Execution Guardrails: Environmental Keying
- Defense ImpairmentDisable or Modify Tools
- Command and ControlApplication Layer Protocol · Application Layer Protocol: Web Protocols
Initial Access TA0001
T1566Phishing×1
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
Execution TA0002
T1059Command and Scripting Interpreter×1
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
T1106Native API×1
Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
Persistence TA0003
T1543Create or Modify System Process×1
Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence. When operating systems boot up, they can start processes that perform background system functions. On Windows and Linux, these system processes are referred to as services. On macOS, launchd processes known as Launch Daemon and Launch Agent are run to finish system initialization and load user specific parameters.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
Privilege Escalation TA0004
T1055Process Injection×1
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
T1055.002Process Injection: Portable Executable Injection×1
Adversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate privileges. PE injection is a method of executing arbitrary code in the address space of a separate live process.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
T1543Create or Modify System Process×1
Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence. When operating systems boot up, they can start processes that perform background system functions. On Windows and Linux, these system processes are referred to as services. On macOS, launchd processes known as Launch Daemon and Launch Agent are run to finish system initialization and load user specific parameters.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
Stealth TA0005
T1055Process Injection×1
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
T1055.002Process Injection: Portable Executable Injection×1
Adversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate privileges. PE injection is a method of executing arbitrary code in the address space of a separate live process.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
T1070Indicator Removal×1
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
T1070.004Indicator Removal: File Deletion×1
Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
T1140Deobfuscate/Decode Files or Information×1
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
T1480Execution Guardrails×1
Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target. Guardrails ensure that a payload only executes against an intended target and reduces collateral damage from an adversary’s campaign. Values an adversary can provide about a target system or environment to use as guardrails may include specific network share names, attached physical devices, files, joined Active Directory (AD) domains, and local/external IP addresses.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
T1480.001Execution Guardrails: Environmental Keying×1
Adversaries may environmentally key payloads or other features of malware to evade defenses and constraint execution to a specific target environment. Environmental keying uses cryptography to constrain execution or actions based on adversary supplied environment specific conditions that are expected to be present on the target. Environmental keying is an implementation of Execution Guardrails that utilizes cryptographic techniques for deriving encryption/decryption keys from specific types of values in a given computing environment.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
Defense Impairment TA0112
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
Command and Control TA0011
T1071Application Layer Protocol×1
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-05-26/lazarus-remotepe-a-three-stage-memory-only-rat-that-unhooks · ATT&CK page ↗
Entries about RemotePE (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- attack.mitre.org11 (85%)
- blog.fox-it.com1 (8%)
- thehackernews.com1 (8%)
All cited sources (13)
- attack.mitre.org`T1055.002`https://attack.mitre.org/techniques/T1055/002/
- attack.mitre.org`T1059`https://attack.mitre.org/techniques/T1059/
- attack.mitre.org`T1070.004`https://attack.mitre.org/techniques/T1070/004/
- attack.mitre.org`T1071.001`https://attack.mitre.org/techniques/T1071/001/
- attack.mitre.org`T1106`https://attack.mitre.org/techniques/T1106/
- attack.mitre.org`T1140`https://attack.mitre.org/techniques/T1140/
- attack.mitre.org`T1480.001`https://attack.mitre.org/techniques/T1480/001/
- attack.mitre.org`T1543.003`https://attack.mitre.org/techniques/T1543/003/
- attack.mitre.org`T1562.001`https://attack.mitre.org/techniques/T1562/001/
- attack.mitre.org`T1562.006`https://attack.mitre.org/techniques/T1562/006/
- attack.mitre.org`T1566`https://attack.mitre.org/techniques/T1566/
- blog.fox-it.comFox-IT, 2026-05-22https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/
- thehackernews.comThe Hacker News, 2026-05-25https://thehackernews.com/2026/05/lazarus-deploys-remotepe-memory-only.html