Nickel Alley

2026-03-23 • Secure WorksNICKEL ALLEY

Nickel Alley is a North Korean government-aligned threat group tracked by the Sophos Counter Threat Unit as an operator of the Contagious Interview campaign. Sophos publicly profiled the group in March 2026, describing attacks that lure technology professionals with fabricated companies, job advertisements, interviews, skills assessments, and code repositories. Since at least 2024, the actor has persuaded developers to execute malicious projects that install BeaverTail or OtterCookie, while campaigns from mid-2025 used ClickFix instructions to deploy GoLangGhost and PyLangGhost. These tools steal browser credentials, cookies, cryptocurrency-wallet data, files, and system information and provide remote command execution. Nickel Alley also compromises or typosquats package repositories and abuses developer tooling and cloud hosting. Its primary objective is cryptocurrency theft, although Sophos observed indications that access could support supply-chain compromise or corporate espionage against finance and technology organizations.

Related Actors

Related Reports in This Cluster

Top Authors

View Nickel Alley reports only

View Nickel Alley reports only