NICKEL ALLEY strategy: Fake it 'til you make it
2026-03-27T20:51:38Z•7586de545aa48da3ab699653e0c4e78d906a972a40d77a77166c4d0e660e569a
AndroidCVE-2026-21992IranKeenaduNICKEL ALLEYNorth KoreaOraclePatch Tuesdaycryptocurrency theftfirmware malwareinitial accessthreat-researchvulnerabilities
What happened
Sophos published multiple threat-research and product posts (Mar 2026): a NICKEL ALLEY campaign (North Korea-linked) abusing fake companies, job postings and code repos to target developers and steal cryptocurrency; discovery of Keenadu firmware-level malware shipping on some Android devices that grants attacker control (primarily used for ad fraud); an Oracle vulnerability disclosed as CVE-2026-21992 impacting core products; the March Patch Tuesday roundup (84 CVEs including eight Critical-severity bugs, none in Windows); and analysis of initial-access techniques used by Iran-linked threat--
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 7586de545aa48da3ab699653e0c4e78d906a972a40d77a77166c4d0e660e569a
- Enrichment time
- 2026-03-27T20:51:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.