RemotePE: The Lazarus RAT that lives in memory (opens in new tab)
Authors: Yun Zheng Hu and Mick Koomen Summary Last year, we published research about a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations, encountered during multiple incident response engagements. This Lazarus subgroup overlaps with activity linked to AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces. In one investigation, we observed that the actor had replaced … Continue reading RemotePE: The Lazarus RAT that lives in memory →
Read the original article