RemotePE: The Lazarus RAT that lives in memory

Authors: Yun Zheng Hu and Mick Koomen Summary Last year, we published research about a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations, encountered during multiple incident response engagements. This Lazarus subgroup overlaps with activity linked to AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces. In one investigation, we observed that the actor had replaced … Continue reading RemotePE: The Lazarus RAT that lives in memory

This article has been indexed from Fox-IT International blog

Read the original article: