lazarusholic

Everyday is lazarus.dayβ

More Fake Devs, More Fake Companies: vexxloso and Nixsora.com

2026-04-26, NKInternet
https://nkinternet.com/2026/04/26/more-fake-devs-more-fake-companies-vexxloso-and-nixsora-com/
#ITWorker

Contents

If you haven’t read part 1, you can read it here: https://nkinternet.com/2026/04/07/npm-malware-fake-devs-and-deepfake-videos-these-are-a-few-of-my-favorite-dprk-things/
In order to keep the first part of this short the plan was to break it into a series of smaller posts. However, within 7 days after publishing the last post most of the accounts were taken down. So what’s left and what accounts did they pivot to?
Mentonex Slack
One thing that wasn’t included in the first post was screenshots of the Mentonex Slack channel. This was designed to appear to look like a legitimate company. There were messages posted about the company and a number of accounts that all appeared to be regular users.
A list of users was also obtained. Several of them appeared to be copied from other legitimate users on LinkedIn. One profile of note is Charl Lucy who we’ll see more of in a few minutes.
This is a technique used by the DPRK on several occasions …