#Graphalgo

Malware/Tool

2026-02-11 • Fake recruiter campaign targets crypto developers with RAT

Graphalgo is the name of a Lazarus fake-recruiter campaign rather than a clearly separated malware family. Operators created convincing blockchain-company personas and GitHub organizations, sent JavaScript and Python developers coding tests, and embedded malicious dependencies in npm, PyPI, or GitHub release artifacts. Multi-stage downloaders ultimately installed a token-protected remote-access Trojan that periodically fetched commands, uploaded and downloaded files, listed processes, ran arbitrary commands, and checked for the MetaMask browser extension. Equivalent final payloads appeared in JavaScript, Python, and VBS.

Tagged Reports

« Back