PULSE NAME
Fake recruiter campaign targets crypto developers with RAT
WHITE Lazarus Group AlienVault 2026-04-13 Modified: 2026-04-13
319
IOCs
HIGH VOLUME
A sophisticated fake recruitment campaign named 'graphalgo' has been active since May 2025, targeting JavaScript and Python developers in the cryptocurrency sector. Attackers approach victims through LinkedIn, Facebook, and Reddit with fabricated job opportunities from fake blockchain companies like Veltrix Capital. The campaign uses malicious dependencies hidden in npm and PyPI packages, delivered through coding test repositories on GitHub. Notable is the bigmathutils package that accumulated over 10,000 downloads before its malicious version was released. The operation deploys a remote access trojan (RAT) with token-protected C2 communication, file manipulation capabilities, and functionality to detect the Metamask browser extension, indicating focus on cryptocurrency theft. The modular campaign design allows threat actors to maintain backend infrastructure while easily replacing compromised frontend elements.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
graphalgo bigmathutils graphnetworkx graphlibcore netstruct terminalcolor256 graphkitx graphchain graphflux graphorbit graphnet graphhub terminal-kleur graphrix bignumx bignumberx bignumex bigmathex bigmathlib bigmathix graphlink graphflowx graphex graphlibx graphdict graphnode graphsync bigpyx bignum
Indicators of Compromise (60 / 319 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0ad0f487a9423dc77949d3a235b96a1d 2026-04-13
FileHash-MD5 0eb5d17f6c48e108355e26271ce1c115 2026-04-13
FileHash-MD5 0f2d18e58c6160f347cda6707ae81f30 2026-04-13
FileHash-MD5 204882fd8d184e268ce810a548db4284 2026-04-13
FileHash-MD5 2a1290d839245d8ab7fab54b3374511c 2026-04-13
FileHash-MD5 2bbe5b60e04891a8a8856a81b2b1cf6e 2026-04-13
FileHash-MD5 2caffeb59591261120ba43c8df937cd6 2026-04-13
FileHash-MD5 3492aead8bbc9184d69f25bb04eed5ca 2026-04-13
FileHash-MD5 3c1a44a8fb59cf0d7fc1adbb2ff92e9e 2026-04-13
FileHash-MD5 40cd39ac67133aba9aa6c17b8a0982bd 2026-04-13
FileHash-MD5 47d06b0a7287a50a364cd02cfc55b05a 2026-04-13
FileHash-MD5 4c67895ef5215dde218f102aac423cd7 2026-04-13
FileHash-MD5 4cc1e104a41aaafe84a867258ef43caf 2026-04-13
FileHash-MD5 4f5901e1b281d5d7a11c6d3643e80a42 2026-04-13
FileHash-MD5 52181b75362bc2a2ff611ef9d02c397f 2026-04-13
FileHash-MD5 58dde1adb94f541bb0c5e77077b227ed 2026-04-13
FileHash-MD5 5d1fb7162cdb32eaca2f84f5aea8bcf8 2026-04-13
FileHash-MD5 5ed917ccd2a023f1d2bf1a9ed0b10baf 2026-04-13
FileHash-MD5 6416c527afd6f4b51ef8c394bfd275de 2026-04-13
FileHash-MD5 68033844eb2bdee6b3448c00b811f90d 2026-04-13
FileHash-MD5 698d7d28e48d774130bf5546fac61f6e 2026-04-13
FileHash-MD5 6ad8f2f50f29efceb636352e8e7dbd1d 2026-04-13
FileHash-MD5 6f8ba278f9f3eb52e73fb34ce1f9e32f 2026-04-13
FileHash-MD5 7d60cb0d8757402a539df5463cb0073c 2026-04-13
FileHash-MD5 7f862419c493c2c56105f7ee529452f4 2026-04-13
FileHash-MD5 84d2ac914467d8251ff228d6757c57a2 2026-04-13
FileHash-MD5 8bdff5d3d8822c6f47a2e6f33f1fb5cd 2026-04-13
FileHash-MD5 8e1a088109bff60b51c89956e310aa10 2026-04-13
FileHash-MD5 93fc111d82caa4881a1fc11a683f3343 2026-04-13
FileHash-MD5 96f466c9f9a1cacfc1b02a7d524ac395 2026-04-13
FileHash-MD5 99b9e8894726d0ed9e9302e952283492 2026-04-13
FileHash-MD5 9c129e14c522a0a6d3e310067dc22800 2026-04-13
FileHash-MD5 a3daa30632e1a06fe578f73c3e44b36f 2026-04-13
FileHash-MD5 a495e9f32fc499ed26fbbc904842bdfb 2026-04-13
FileHash-MD5 a4fcc8f59c84e1bf2af8285d83210fc7 2026-04-13
FileHash-MD5 a5dd3601da6d65ac5100873471ca9dab 2026-04-13
FileHash-MD5 b061b17dd978a84335c072428323d71b 2026-04-13
FileHash-MD5 b307f67aa06d6678f84db33413f4d991 2026-04-13
FileHash-MD5 b4fcc4610344f21e618486ada59be10d 2026-04-13
FileHash-MD5 ba62d2a52b02244e739132327100747f 2026-04-13
FileHash-MD5 c171deea8132a77abf4c2f12dc2487c8 2026-04-13
FileHash-MD5 c5be9231768925ff6c0afddffbb1fbda 2026-04-13
FileHash-MD5 c70aa2d6fa6779c95938d2ca49a13d5b 2026-04-13
FileHash-MD5 ca5d8e6a729219216bcc7e59e1e92e5d 2026-04-13
FileHash-MD5 cb22a6c8a756e066a8c08d77c6318f76 2026-04-13
FileHash-MD5 cb2aadb965a0bb4cee387636e8b109d7 2026-04-13
FileHash-MD5 cffb88bbdf9f0c1bff7fea9e5176fb9f 2026-04-13
FileHash-MD5 d3821f15663056144bcc4e722bcaa8ae 2026-04-13
FileHash-MD5 d5f5a46bddfd2fa40597cdf0b1125698 2026-04-13
FileHash-MD5 ddef73ccbd032ab29402e7fb270304b8 2026-04-13
FileHash-MD5 e16f3d2f577004410e1ff3e258e9bbac 2026-04-13
FileHash-MD5 e4b04f0778f0793ab53cd27b984f60dc 2026-04-13
FileHash-MD5 edc08a5e4378fc9079b619a06248999f 2026-04-13
FileHash-MD5 f418bb433cd972517b087cfcb2a85739 2026-04-13
FileHash-MD5 f6204afbb373adc75119f7190f2253bb 2026-04-13
FileHash-MD5 f68cfe775147399cb2c026b381c9d21f 2026-04-13
FileHash-MD5 f6a57b870ba2432183ced28dfbccc7b9 2026-04-13
FileHash-MD5 f6bcfb203a54ec47e5dafd648f39ef98 2026-04-13
FileHash-MD5 f9ee9082dadb91f70ee4a615cca38fcc 2026-04-13
FileHash-MD5 fca1f02389f13136bcc299a3fc32c08f 2026-04-13