NICKEL ALLEY strategy: Fake it ‘til you make it

2026-03-23 Sophos

https://www.sophos.com/en-us/blog/nickel-alley-strategy-fake-it-til-you-make-it

Thumbnail for NICKEL ALLEY strategy: Fake it ‘til you make it

Sophos CTU reports that NICKEL ALLEY, a North Korean government-linked group, continued Contagious Interview operations against technology professionals through fake companies, fake jobs, malicious GitHub repositories, and developer assessment lures. Since at least mid-2025, the group has used ClickFix-style prompts that tell victims to run local commands which download archives from attacker-controlled domains, execute VBScript, and launch PyLangGhost RAT through a renamed Python binary. PyLangGhost supports file exfiltration, arbitrary command execution, system profiling, browser credential and cookie theft, and targeting of Chrome cryptocurrency wallet extension data, aligning with the campaign’s financial motivation. Sophos also observed GitHub and npm-based developer infection paths, including BeaverTail retrieval via Vercel-hosted payloads and VS Code tasks configured to run curl or wget commands when a project folder is opened.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0f010280ee2a91a57b0edf8f18c0091… 2026-03-23 2026-03-23
HASH 52f173a760db5d68e52ba1f1ac51c023 2026-03-23 2026-03-23
HASH ac26ecf52002d87f3ba89f9e1b0742e… 2026-03-23 2026-03-23
HASH 5e307ef3aa9f20d963382700173530c… 2026-03-23 2026-03-23
HASH e9b9d86a22f9795d42632650a78d57df 2026-03-23 2026-03-23
HASH 2151d4d7dc8d6dca7242928a17ea3fb… 2026-03-23 2026-03-23
HASH a55629dc112ee133ac8dba80549cb0c7 2026-03-23 2026-03-23
HASH 1b42fc77155bd78b098e0b72440dd72… 2026-03-23 2026-03-23
HASH 58c1e49c67e5b7bcf10d30e370685d1… 2026-03-23 2026-03-23
HASH 5ee13db6a646a9de00bbeec6030677e… 2026-03-23 2026-03-23
HASH de05ecc9f0136246d01609231080266… 2026-03-23 2026-03-23
HASH 1d652e7ab71621c7245bfbf84bacdc3e 2026-03-23 2026-03-23
URL https://astrabytesyncs.com 2026-03-23 2026-03-23
URL https://rgg-test.vercel.app/api… 2026-03-23 2026-03-23
URL https://ake-test.vercel.app/api… 2026-03-23 2026-03-23
URL https://vscode-ext-git.vercel.a… 2026-03-23 2026-03-23
URL https://astraluck-vercel.vercel… 2026-03-23 2026-03-23
URL https://rgg-vercel.vercel.app/a… 2026-03-23 2026-03-23
URL https://astrahub.vercel.app/api… 2026-03-23 2026-03-23
DOMAIN astrabytesync.com 2026-03-23 2026-03-23
DOMAIN astrabytesyncs.com 2026-03-23 2026-03-23
DOMAIN publicshare.org 2026-03-23 2026-03-23
IPv4 144.172.93.88 2026-03-05 2026-03-23
IPv4 95.169.180.140 2025-11-23 2026-03-23
DOMAIN chainlink-api-v3.com 2025-10-21 2026-03-23

Related Actors

Related Reports

« Back