NICKEL ALLEY strategy: Fake it ‘til you make it
2026-03-23 • Sophos •
https://www.sophos.com/en-us/blog/nickel-alley-strategy-fake-it-til-you-make-it
Sophos CTU reports that NICKEL ALLEY, a North Korean government-linked group, continued Contagious Interview operations against technology professionals through fake companies, fake jobs, malicious GitHub repositories, and developer assessment lures. Since at least mid-2025, the group has used ClickFix-style prompts that tell victims to run local commands which download archives from attacker-controlled domains, execute VBScript, and launch PyLangGhost RAT through a renamed Python binary. PyLangGhost supports file exfiltration, arbitrary command execution, system profiling, browser credential and cookie theft, and targeting of Chrome cryptocurrency wallet extension data, aligning with the campaign’s financial motivation. Sophos also observed GitHub and npm-based developer infection paths, including BeaverTail retrieval via Vercel-hosted payloads and VS Code tasks configured to run curl or wget commands when a project folder is opened.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 0f010280ee2a91a57b0edf8f18c0091… | 2026-03-23 | 2026-03-23 |
| HASH | 52f173a760db5d68e52ba1f1ac51c023 | 2026-03-23 | 2026-03-23 |
| HASH | ac26ecf52002d87f3ba89f9e1b0742e… | 2026-03-23 | 2026-03-23 |
| HASH | 5e307ef3aa9f20d963382700173530c… | 2026-03-23 | 2026-03-23 |
| HASH | e9b9d86a22f9795d42632650a78d57df | 2026-03-23 | 2026-03-23 |
| HASH | 2151d4d7dc8d6dca7242928a17ea3fb… | 2026-03-23 | 2026-03-23 |
| HASH | a55629dc112ee133ac8dba80549cb0c7 | 2026-03-23 | 2026-03-23 |
| HASH | 1b42fc77155bd78b098e0b72440dd72… | 2026-03-23 | 2026-03-23 |
| HASH | 58c1e49c67e5b7bcf10d30e370685d1… | 2026-03-23 | 2026-03-23 |
| HASH | 5ee13db6a646a9de00bbeec6030677e… | 2026-03-23 | 2026-03-23 |
| HASH | de05ecc9f0136246d01609231080266… | 2026-03-23 | 2026-03-23 |
| HASH | 1d652e7ab71621c7245bfbf84bacdc3e | 2026-03-23 | 2026-03-23 |
| URL | https://astrabytesyncs.com | 2026-03-23 | 2026-03-23 |
| URL | https://rgg-test.vercel.app/api… | 2026-03-23 | 2026-03-23 |
| URL | https://ake-test.vercel.app/api… | 2026-03-23 | 2026-03-23 |
| URL | https://vscode-ext-git.vercel.a… | 2026-03-23 | 2026-03-23 |
| URL | https://astraluck-vercel.vercel… | 2026-03-23 | 2026-03-23 |
| URL | https://rgg-vercel.vercel.app/a… | 2026-03-23 | 2026-03-23 |
| URL | https://astrahub.vercel.app/api… | 2026-03-23 | 2026-03-23 |
| DOMAIN | astrabytesync.com | 2026-03-23 | 2026-03-23 |
| DOMAIN | astrabytesyncs.com | 2026-03-23 | 2026-03-23 |
| DOMAIN | publicshare.org | 2026-03-23 | 2026-03-23 |
| IPv4 | 144.172.93.88 | 2026-03-05 | 2026-03-23 |
| IPv4 | 95.169.180.140 | 2025-11-23 | 2026-03-23 |
| DOMAIN | chainlink-api-v3.com | 2025-10-21 | 2026-03-23 |