๐Ÿ“ฐ Lazarus Group Unleashes 'RemotePE' Memory-Only RAT in Attacks on Financial and Crypto Firms

๐Ÿ‡ฐ๐Ÿ‡ต Lazarus Group deploys new 'RemotePE' memory-only RAT against financial & crypto firms. The fileless malware evades detection by never touching the disk, using a multi-stage infection chain. #LazarusGroup #Malware #ThreatIntel #RemotePE

๐ŸŒ cyber[.]netsecops[.]io

๐Ÿ”— https://cyber.netsecops.io/articles/lazarus-group-deploys-memory-only-rat-remotepe-in-financial-attacks/?utmโ€ฆ

Lazarus Group Unleashes 'RemotePE' Memory-Only RAT in Attacks on Financial and Crypto Firms

The North Korean Lazarus Group is using a new memory-only RAT, RemotePE, in sophisticated attacks targeting the financial and cryptocurrency sectors to evade detection and steal assets.

CyberNetSec.io

๐Ÿ“ฐ Lazarus Group Unleashes 'RemotePE' Memory-Only RAT in Attacks on Financial and Crypto Firms

๐Ÿ‡ฐ๐Ÿ‡ต Lazarus Group deploys new 'RemotePE' memory-only RAT against financial & crypto firms. The fileless malware evades detection by never touching the disk, using a multi-stage infection chain. #LazarusGroup #Malware #ThreatIntel #RemotePE

๐ŸŒ cyber[.]netsecops[.]io

๐Ÿ”— https://cyber.netsecops.io/articles/lazarus-group-deploys-memory-only-rat-remotepe-in-financial-attacks/?utmโ€ฆ

Lazarus Group Deploys Memory-Only RAT in Financial Sector Attacks

The notorious Lazarus Group has unleashed a sneaky new attack tool, a memory-only Remote Access Trojan (RAT), targeting the financial sector with cunning precision. This stealthy malware, known as RemotePE, is just the latest weapon in the group's arsenal, and it's being used to infiltrate and manipulate its victims.

https://osintsights.com/lazarus-group-deploys-memory-only-rat-in-financial-sector-attacks?utm_source=mastodon&utm_medium=social

#LazarusGroup #RemoteAccessTrojan #Rat #FinancialSector #DecentralizedFinance

Lazarus Group Deploys Memory-Only RAT in Financial Sector Attacks

Learn how Lazarus Group deploys a memory-only RAT in financial sector attacks using RemotePE, and protect your organization now with expert insights.

OSINTSights

Banking Trojan Targets Crypto Firms with Sophisticated Attacks

A new banking Trojan, dubbed TCLBanker, is wreaking havoc on crypto and finance platforms, allowing hackers to remotely control infected systems and steal sensitive info. This sophisticated attack, linked to North Korea's notorious Lazarus Group, has already led to the largest crypto platform hack of 2026.

https://osintsights.com/banking-trojan-targets-crypto-firms-with-sophisticated-attacks?utm_source=mastodon&utm_medium=social

#Tclbanker #BankingTrojan #LazarusGroup #NorthKorea #CryptoFirms

Banking Trojan Targets Crypto Firms with Sophisticated Attacks

Learn how TCLBanker, a banking Trojan, targets crypto and finance platforms with sophisticated attacks, and protect your business from this growing threat now.

OSINTSights

La Corea del Nord ha rubato il 76% di tutte le criptovalute hackerate nel 2026: due attacchi, $577 milioni, e una macchina da guerra finanziata dal cyber

Con solo due operazioni nel primo quadrimestre 2026, gli hacker nordcoreani hanno sottratto $577 milioni in criptovalute โ€” il 76% di tutti i furti crypto globali. TRM Labs documenta come Pyongyang abbia trasformato il crimine DeFi in motore finanziario del proprio programma nucleare.

https://insicurezzadigitale.com/la-corea-del-nord-ha-rubato-il-76-di-tutte-le-criptovalute-hackerate-nel-2026-due-attacchi-577-milioni-e-una-macchina-da-guerra-finanziata-dal-cyber/

i suspect #northkorea has figured out how to use AI for #cybersecurity purposes

#crypto #DPRK #infosec #threatintel #cryptocurrency #lazarusGroup #defi

BlueNoroff e le riunioni Zoom fasulle: come la Corea del Nord usa lโ€™IA e i deepfake per svuotare i portafogli crypto dei CEO

Il gruppo nordcoreano BlueNoroff ha perfezionato un attacco multi-stadio che combina deepfake generati con ChatGPT, finte videochiamate Zoom e tecniche ClickFix per compromettere i dirigenti del settore Web3 in meno di cinque minuti. Arctic Wolf documenta la pipeline di produzione deepfake che si autoalimenta partendo dai filmati rubati alle vittime precedenti.

https://insicurezzadigitale.com/bluenoroff-e-le-riunioni-zoom-fasulle-come-la-corea-del-nord-usa-lia-e-i-deepfake-per-svuotare-i-portafogli-crypto-dei-ceo/

Contagious Interview diventa un worm: Void Dokkaebi trasforma 750 repository in vettori auto-propaganti contro gli sviluppatori

Il gruppo APT nordcoreano Void Dokkaebi (Famous Chollima) ha trasformato le sue finte offerte di lavoro in un attacco supply chain capace di propagarsi automaticamente: basta aprire un repository clonato in VS Code per attivare payload nascosti in commit manipolati. A marzo 2026, Trend Micro ha mappato oltre 750 repository infetti, 500 task.json malevoli e staging C2 su Tron, Aptos e Binance Smart Chain.

https://insicurezzadigitale.com/contagious-interview-diventa-un-worm-void-dokkaebi-trasforma-750-repository-in-vettori-auto-propaganti-contro-gli-sviluppatori/

Lazarus Group Targets KelpDAO in $290m Crypto Heist

In a shocking crypto heist, North Korea's notorious Lazarus Group is accused of swiping $290 million from KelpDAO, raising questions about accountability in the digital age. This brazen theft is a stark reminder of the threats lurking in the shadows of the cryptocurrency world.

https://osintsights.com/lazarus-group-targets-kelpdao-in-290m-crypto-heist?utm_source=mastodon&utm_medium=social

#LazarusGroup #NorthKorea #CryptoHeist #290mCryptoTheft #Kelpdao

Lazarus Group Targets KelpDAO in $290m Crypto Heist

Lazarus Group steals $290m in crypto from KelpDAO, learn how to protect your assets now and prevent similar attacks.

OSINTSights