Lazarus Group RemotePE long-term observation campaign against financial and cryptocurrency organizations
Campaign
Summary
Hide ▲
Show ▼
The Lazarus Group was tied to a RemotePE campaign against financial and cryptocurrency organizations, signaling a stealth-focused operation with sustained access risk. The tooling relied on memory-only execution, EDR evasion, and a low forensic footprint to reduce detection. Activity evidence spans mid-2023 to mid-2024, indicating a long-running campaign rather than a short-lived intrusion.
Related Happenings
RemotePE memory-only RAT activity by Lazarus Group targeting financial and cryptocurrency organizations
Malware Activity
H score28
First: 25.05.2026 12:32
Last: 25.05.2026 12:32
Sources 1
How related:
Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations.
About this happening:
The RemotePE malware has been tied to Lazarus Group activity against financial and cryptocurrency organizations, raising the risk of stealthy long-term access and late...
RemotePE memory-only RAT activity by Lazarus Group targeting financial and cryptocurrency organizations
Malware ActivityHow related: Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations.
About this happening: The RemotePE malware has been tied to Lazarus Group activity against financial and cryptocurrency organizations, raising the risk of stealthy long-term access and late...
Handala multi-stage malware with Telegram C2 and exfiltration
Malware Activity
H score22
First: 24.03.2026 11:30
Last: 24.03.2026 11:30
Sources 1
About this happening:
The Handala malware package uses a multi-stage payload to give operators remote access to infected Windows devices, increasing the risk of stealthy data theft. The...
Handala multi-stage malware with Telegram C2 and exfiltration
Malware ActivityAbout this happening: The Handala malware package uses a multi-stage payload to give operators remote access to infected Windows devices, increasing the risk of stealthy data theft. The...
Lazarus-associated Medusa extortion campaign targeting U.S. healthcare organizations
Campaign
H score39
First: 24.02.2026 13:00
Last: 24.02.2026 13:00
Sources 1
About this happening:
A Lazarus-associated Medusa ransomware campaign is targeting U.S. healthcare organizations, raising the risk of extortion, data encryption, and operational dis...
Lazarus-associated Medusa extortion campaign targeting U.S. healthcare organizations
CampaignAbout this happening: A Lazarus-associated Medusa ransomware campaign is targeting U.S. healthcare organizations, raising the risk of extortion, data encryption, and operational dis...
BlueNoroff spear-phishing campaign uses typosquatted Zoom, Teams, and Calendly lures against crypto firms
Campaign
H score33
First: 11.02.2026 00:17
Last: 11.02.2026 00:17
Sources 1
About this happening:
Separate analyses described North Korea-linked operators associated with UNC1069 and BlueNoroff using social engineering against cryptocurrency targets and a fin...
BlueNoroff spear-phishing campaign uses typosquatted Zoom, Teams, and Calendly lures against crypto firms
CampaignAbout this happening: Separate analyses described North Korea-linked operators associated with UNC1069 and BlueNoroff using social engineering against cryptocurrency targets and a fin...
Labyrinth Chollima split into three North Korean hacking groups
Threat Actor Meta
H score26
First: 30.01.2026 17:40
Last: 30.01.2026 17:40
Sources 1
About this happening:
Labyrinth Chollima has been split into three tracked North Korean groups, reshaping how defenders map a major DPRK cyber ecosystem and its target set. Golden Chollima...
Labyrinth Chollima split into three North Korean hacking groups
Threat Actor MetaAbout this happening: Labyrinth Chollima has been split into three tracked North Korean groups, reshaping how defenders map a major DPRK cyber ecosystem and its target set. Golden Chollima...
Timeline
-
25.05.2026 12:32 2 articles · 1mo ago
Lazarus Group RemotePE long-term observation campaign against financial and cryptocurrency organizations
Initial DisclosureInitial access was obtained through social engineering on Telegram and fake Calendly and Picktime domains, leading to compromise of an employee device. The earliest loader artifact dates to November 2023, showing the operation had already advanced into a staged intrusion chain.
Show sources
- Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms — thehackernews.com — 25.05.2026 12:32
- Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms — thehackernews.com — 25.05.2026 12:32