SYMBOLCOMMON_NAMEaka. SYNONYMS
win.remotepe (Back to overview)

RemotePE

Actor(s): Lazarus Group

VTCollection    

According to Fox-IT, RemotePE is the final-stage in-memory RAT that operates across multiple threads to handle C2 communication and command execution. It exposes a range of capabilities via a structured command set, including configuration, console access, file and process operations, and plugin support to dynamically load additional payloads. The framework emphasizes memory-only execution and encrypted, compressed exchanges with the C2, aiming to minimize forensic traces and enable long-term, stealthy control managed by an operator.

References
2026-05-22 ⋅ Fox-IT ⋅ Mick Koomen, Yun Zheng Hu
RemotePE: The Lazarus RAT that lives in memory
DPAPILoader RemotePE
Yara Rules
[TLP:WHITE] win_remotepe_auto (20260917 | Detects win.remotepe.)
rule win_remotepe_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.remotepe."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.remotepe"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 488b842430010000 488b08 e8???????? 0fbe00 83f82e 0f85ff000000 488b842430010000 }
            // n = 7, score = 100
            //   488b842430010000     | mov                 dword ptr [esp + 0x38], eax
            //   488b08               | mov                 dl, 0x22
            //   e8????????           |                     
            //   0fbe00               | dec                 eax
            //   83f82e               | mov                 ecx, dword ptr [esp + 0x58]
            //   0f85ff000000         | dec                 eax
            //   488b842430010000     | sub                 esp, 0x48

        $sequence_1 = { 4533c0 e8???????? 33c0 4c8d5c2460 498b5b10 498b6b18 498b7320 }
            // n = 7, score = 100
            //   4533c0               | dec                 eax
            //   e8????????           |                     
            //   33c0                 | lea                 ecx, [esp + 0x90]
            //   4c8d5c2460           | dec                 eax
            //   498b5b10             | mov                 ecx, dword ptr [esp + 0x28]
            //   498b6b18             | movzx               eax, al
            //   498b7320             | test                eax, eax

        $sequence_2 = { 488b4608 488b3cd0 4c3bc7 0f8699000000 482bcf 498d9effff0000 4803d9 }
            // n = 7, score = 100
            //   488b4608             | jbe                 0x153c
            //   488b3cd0             | mov                 edx, 4
            //   4c3bc7               | inc                 esp
            //   0f8699000000         | lea                 eax, [edx + 0x17]
            //   482bcf               | dec                 eax
            //   498d9effff0000       | mov                 edx, ebp
            //   4803d9               | dec                 eax

        $sequence_3 = { 7710 488d053f570000 488d0de4510000 eb11 33c0 c3 488d05c84c0000 }
            // n = 7, score = 100
            //   7710                 | dec                 eax
            //   488d053f570000       | sar                 ecx, 6
            //   488d0de4510000       | dec                 eax
            //   eb11                 | lea                 edx, [edx + edx*8]
            //   33c0                 | dec                 ecx
            //   c3                   | mov                 ecx, dword ptr [eax + ecx*8]
            //   488d05c84c0000       | dec                 eax

        $sequence_4 = { 7404 48896b08 48896b10 b001 eb14 ba12000000 488b4c2460 }
            // n = 7, score = 100
            //   7404                 | mov                 ecx, esi
            //   48896b08             | movzx               edx, word ptr [edi + 0x50]
            //   48896b10             | dec                 eax
            //   b001                 | mov                 ecx, esi
            //   eb14                 | dec                 eax
            //   ba12000000           | mov                 ecx, dword ptr [edi + 0x50]
            //   488b4c2460           | inc                 ecx

        $sequence_5 = { 488b542438 488b4c2460 e8???????? 89442420 837c242000 7c0b 48c744244001000000 }
            // n = 7, score = 100
            //   488b542438           | mov                 edx, dword ptr [esp + 0x20]
            //   488b4c2460           | dec                 eax
            //   e8????????           |                     
            //   89442420             | mov                 ecx, eax
            //   837c242000           | dec                 eax
            //   7c0b                 | add                 eax, 8
            //   48c744244001000000     | dec    eax

        $sequence_6 = { d1e8 33442414 488b4c2450 488b1424 338491f80f0000 488b4c2450 488b1424 }
            // n = 7, score = 100
            //   d1e8                 | dec                 eax
            //   33442414             | mov                 edx, ebp
            //   488b4c2450           | jmp                 0x975
            //   488b1424             | dec                 eax
            //   338491f80f0000       | mov                 ecx, ebx
            //   488b4c2450           | je                  0x985
            //   488b1424             | inc                 ecx

        $sequence_7 = { f3aa 8b8424d8000000 83e820 8bc8 e8???????? 4889442460 48837c246000 }
            // n = 7, score = 100
            //   f3aa                 | je                  0x267
            //   8b8424d8000000       | mov                 dword ptr [eax + 4], ecx
            //   83e820               | dec                 eax
            //   8bc8                 | mov                 eax, dword ptr [esp + 0x28]
            //   e8????????           |                     
            //   4889442460           | mov                 ecx, dword ptr [esp + 0xc8]
            //   48837c246000         | mov                 dword ptr [eax + 8], ecx

        $sequence_8 = { c744244030000000 48c744244800000000 c744245800000000 48c744245000000000 48c744246000000000 48c744246800000000 488d442430 }
            // n = 7, score = 100
            //   c744244030000000     | or                  eax, 2
            //   48c744244800000000     | mov    dword ptr [esp + 0x20], eax
            //   c744245800000000     | movzx               eax, byte ptr [esp + 0x58]
            //   48c744245000000000     | test    eax, eax
            //   48c744246000000000     | jne    0x358
            //   48c744246800000000     | je    0x35a
            //   488d442430           | mov                 eax, dword ptr [esp + 0x20]

        $sequence_9 = { 498bc1 c3 4053 4883ec20 488bd9 488bc2 488d0d69c00200 }
            // n = 7, score = 100
            //   498bc1               | dec                 eax
            //   c3                   | lea                 edx, [esp + 0x20]
            //   4053                 | dec                 eax
            //   4883ec20             | mov                 ecx, eax
            //   488bd9               | dec                 eax
            //   488bc2               | mov                 eax, dword ptr [esp + 0x30]
            //   488d0d69c00200       | dec                 eax

    condition:
        7 of them and filesize < 1104896
}
Download all Yara Rules