Find notable cyber news and cases, enriched with sources, timelines, and signals.

Lazarus Group RemotePE long-term observation campaign against financial and cryptocurrency organizations

Campaign
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

The Lazarus Group was tied to a RemotePE campaign against financial and cryptocurrency organizations, signaling a stealth-focused operation with sustained access risk. The tooling relied on memory-only execution, EDR evasion, and a low forensic footprint to reduce detection. Activity evidence spans mid-2023 to mid-2024, indicating a long-running campaign rather than a short-lived intrusion.

Related Happenings

RemotePE memory-only RAT activity by Lazarus Group targeting financial and cryptocurrency organizations

Malware Activity
H score28 First: 25.05.2026 12:32 Last: 25.05.2026 12:32 Sources 1

How related: Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations.

About this happening: The RemotePE malware has been tied to Lazarus Group activity against financial and cryptocurrency organizations, raising the risk of stealthy long-term access and late...

Handala multi-stage malware with Telegram C2 and exfiltration

Malware Activity
H score22 First: 24.03.2026 11:30 Last: 24.03.2026 11:30 Sources 1

About this happening: The Handala malware package uses a multi-stage payload to give operators remote access to infected Windows devices, increasing the risk of stealthy data theft. The...

Lazarus-associated Medusa extortion campaign targeting U.S. healthcare organizations

Campaign
H score39 First: 24.02.2026 13:00 Last: 24.02.2026 13:00 Sources 1

About this happening: A Lazarus-associated Medusa ransomware campaign is targeting U.S. healthcare organizations, raising the risk of extortion, data encryption, and operational dis...

BlueNoroff spear-phishing campaign uses typosquatted Zoom, Teams, and Calendly lures against crypto firms

Campaign
H score33 First: 11.02.2026 00:17 Last: 11.02.2026 00:17 Sources 1

About this happening: Separate analyses described North Korea-linked operators associated with UNC1069 and BlueNoroff using social engineering against cryptocurrency targets and a fin...

Labyrinth Chollima split into three North Korean hacking groups

Threat Actor Meta
H score26 First: 30.01.2026 17:40 Last: 30.01.2026 17:40 Sources 1

About this happening: Labyrinth Chollima has been split into three tracked North Korean groups, reshaping how defenders map a major DPRK cyber ecosystem and its target set. Golden Chollima...

Timeline

  1. 25.05.2026 12:32 2 articles · 1mo ago

    Lazarus Group RemotePE long-term observation campaign against financial and cryptocurrency organizations

    Initial Disclosure

    Initial access was obtained through social engineering on Telegram and fake Calendly and Picktime domains, leading to compromise of an employee device. The earliest loader artifact dates to November 2023, showing the operation had already advanced into a staged intrusion chain.

    Show sources