Lazarus Group RemotePE long-term observation campaign against financial and cryptocurrency organizations
Campaign
Summary
Hide ▲
Show ▼
The Lazarus Group was tied to a RemotePE campaign against financial and cryptocurrency organizations, signaling a stealth-focused operation with sustained access risk. The tooling relied on memory-only execution, EDR evasion, and a low forensic footprint to reduce detection. Activity evidence spans mid-2023 to mid-2024, indicating a long-running campaign rather than a short-lived intrusion.
Related Happenings
RemotePE memory-only RAT activity by Lazarus Group targeting financial and cryptocurrency organizations
Malware Activity
First: 25.05.2026 12:32
Last: 25.05.2026 12:32
Sources 1
How related:
Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations.
About this happening:
The **RemotePE** malware has been tied to **Lazarus Group** activity against **financial and cryptocurrency organizations**, raising the risk of stealthy long-term access and late...
RemotePE memory-only RAT activity by Lazarus Group targeting financial and cryptocurrency organizations
Malware ActivityHow related: Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations.
About this happening: The **RemotePE** malware has been tied to **Lazarus Group** activity against **financial and cryptocurrency organizations**, raising the risk of stealthy long-term access and late...
Handala multi-stage malware with Telegram C2 and exfiltration
Malware Activity
First: 24.03.2026 11:30
Last: 24.03.2026 11:30
Sources 1
About this happening:
The **Handala** malware package uses a **multi-stage payload** to give operators **remote access** to infected **Windows** devices, increasing the risk of stealthy data theft. The...
Handala multi-stage malware with Telegram C2 and exfiltration
Malware ActivityAbout this happening: The **Handala** malware package uses a **multi-stage payload** to give operators **remote access** to infected **Windows** devices, increasing the risk of stealthy data theft. The...
Lazarus-associated Medusa extortion campaign targeting U.S. healthcare organizations
Campaign
First: 24.02.2026 13:00
Last: 24.02.2026 13:00
Sources 1
About this happening:
A **Lazarus**-associated **Medusa ransomware** campaign is targeting **U.S. healthcare organizations**, raising the risk of **extortion**, **data encryption**, and operational dis...
Lazarus-associated Medusa extortion campaign targeting U.S. healthcare organizations
CampaignAbout this happening: A **Lazarus**-associated **Medusa ransomware** campaign is targeting **U.S. healthcare organizations**, raising the risk of **extortion**, **data encryption**, and operational dis...
BlueNoroff spear-phishing campaign uses typosquatted Zoom, Teams, and Calendly lures against crypto firms
Campaign
First: 11.02.2026 00:17
Last: 11.02.2026 00:17
Sources 1
About this happening:
**BlueNoroff**, a **North Korea-linked Lazarus Group** subgroup, ran a **large-scale spear-phishing campaign** against **100+ cryptocurrency organizations** in **20+ countries** b...
BlueNoroff spear-phishing campaign uses typosquatted Zoom, Teams, and Calendly lures against crypto firms
CampaignAbout this happening: **BlueNoroff**, a **North Korea-linked Lazarus Group** subgroup, ran a **large-scale spear-phishing campaign** against **100+ cryptocurrency organizations** in **20+ countries** b...
Labyrinth Chollima split into three North Korean hacking groups
Threat Actor Meta
First: 30.01.2026 17:40
Last: 30.01.2026 17:40
Sources 1
About this happening:
**Labyrinth Chollima** has been split into **three tracked North Korean groups**, reshaping how defenders map a major DPRK cyber ecosystem and its target set. **Golden Chollima**...
Labyrinth Chollima split into three North Korean hacking groups
Threat Actor MetaAbout this happening: **Labyrinth Chollima** has been split into **three tracked North Korean groups**, reshaping how defenders map a major DPRK cyber ecosystem and its target set. **Golden Chollima**...
Timeline
-
25.05.2026 12:32 2 articles · 2d ago
Lazarus Group RemotePE long-term observation campaign against financial and cryptocurrency organizations
Initial DisclosureInitial access was obtained through **social engineering on Telegram** and fake **Calendly** and **Picktime** domains, leading to compromise of an employee device. The earliest loader artifact dates to **November 2023**, showing the operation had already advanced into a staged intrusion chain.
Show sources
- Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms — thehackernews.com — 25.05.2026 12:32
- Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms — thehackernews.com — 25.05.2026 12:32