Skip to content
Lazarus Group's Graphalgo Campaign Targets Developers with Malware via Fake Job Offers

Lazarus Group's Graphalgo Campaign Targets Developers with Malware via Fake Job Offers

First seen 12 Feb 2026, 17:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

The Lazarus Group, a North Korean hacking team, has initiated a fake recruiter campaign named 'Graphalgo' targeting cryptocurrency developers. Active since May 2025, this operation utilizes fraudulent job offers to distribute remote access trojans through platforms like GitHub, npm, and PyPI, affecting developers in the blockchain and cryptocurrency sectors.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

Timeline

2025-05-01
Lazarus Group's Graphalgo campaign begins
2026-02-12
Cybersecurity news articles published on the campaign

More articles in this cluster (7)

Following this threat?

Track Lazarus Group in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed