logo

NICKEL ALLEY strategy: Fake it ‘til you make it

ID: e3e1a251-8211-5eb1-a5d9-93f68bea18e1

STIX ID: report--e3e1a251-8211-5eb1-a5d9-93f68bea18e1

Feed Name: Sophos Blogs

Threat Score
86/100

Date Published: 2026-03-23

Date Updated: 2026-04-30

...
...

Sophos/CTU researchers report that NICKEL ALLEY, a North Korean-affiliated actor, targets technology and Web3 developers with fake job lures and ClickFix-style assessments to trick victims into running commands that deploy PyLangGhost RAT (and prior GoLangGhost), enabling credential and crypto-wallet theft, file exfiltration, and potential supply-chain or corporate espionage; the report includes infection chain details, IOCs (domains, IPs, hashes), and detection/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.