lazarusholic

Everyday is lazarus.dayβ

NICKEL ALLEY

2026-03-23, SecureWorks
https://www.sophos.com/en-us/threat-profiles/nickel-alley
#NickelAlley

Contents

NICKEL ALLEY
Objectives
Espionage, Surveillance
Aliases
CL-STA-0240 (Palo Alto), Purplebravo Recorded Future, Storm-1877 (Microsoft), Tenacious Pungsan (Data Dog)
Summary
NICKEL ALLEY threat group targets professionals in the tech sector by advertising fake job opportunities. The threat actors deceive prospective candidates through a fake job interview process to ultimately deliver malware. This activity is tracked publicly as the Contagious Interview campaign. NICKEL ALLEY operates on behalf of the North Korean government.