Graphalgo fake recruiter-test campaign respawned

2026-04-09 Reversing Labs

https://www.reversinglabs.com/blog/graphalgo-campaign-respawned

Thumbnail for Graphalgo fake recruiter-test campaign respawned

ReversingLabs found the graphalgo fake recruiter-test campaign continuing with new fake blockchain companies and GitHub organizations designed to make malicious job assignments appear legitimate. The activity used recruiter personas, fake company infrastructure, LinkedIn profiles, and coding tasks to lure developers into running project setup commands that installed a downloader and the same RAT observed in earlier graphalgo operations. Newer branches shifted malicious dependency hosting away from npm and PyPI into GitHub release artifacts referenced deep inside package-lock.json files, including typosquatted repositories that imitate legitimate maintainers. The excerpt notes techniques associated with North Korean threat actors, including likely fake or stolen employee identities and GMT+9 timestamps in malicious repositories, while also linking the campaign’s targeting context to recent North Korea-attributed developer ecosystem operations. The tradecraft matters because it moves supply-chain delivery into places less heavily monitored than package registries and targets developers through believable job-interview workflows.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f1487451933a05a680e71dde7a2b115… 2026-04-09 2026-04-09
HASH 679fdccecfed0e5cc2c2636fe649a66… 2026-04-09 2026-04-09
HASH c7692a6816cc0eb61216358ff0367d7… 2026-04-09 2026-04-09
HASH 5c30d58dc44182f959c8035e990153b… 2026-04-09 2026-04-09
HASH 7a35c8b0e1182b1fd12a8acb49cfeae… 2026-04-09 2026-04-09
HASH eea702ebc53a4b9f8c1b511fffce16f… 2026-04-09 2026-04-09
HASH e4bf38b28b7aeec2685d1d2581d271c… 2026-04-09 2026-04-09
HASH d75b3abbdd7af3b18be945caa721f1e… 2026-04-09 2026-04-09
HASH cb7ac56cf1c3c1aac9fe4c86a9a323b… 2026-04-09 2026-04-09
HASH f6c574baf05234284966abba25377ee… 2026-04-09 2026-04-09
HASH d531769223f468f93e42e19dea74cb1… 2026-04-09 2026-04-09
HASH 173bb313e6e29525fd6b04407c1c6e8… 2026-04-09 2026-04-09
HASH 65de94d3eb0524fc17df5fdec8c20af… 2026-04-09 2026-04-09
HASH e3a71d70a5a5d3790a352955edb3bb7… 2026-04-09 2026-04-09
HASH c4326153401904e82b17726864be65c… 2026-04-09 2026-04-09
HASH ebb4630024764bdf5e5c1013166cc46… 2026-04-09 2026-04-09
HASH 7af1065e7e6fb6184f99541d142132b… 2026-04-09 2026-04-09
DOMAIN veltrixcap.org 2026-04-09 2026-04-09

Related Reports

« Back