NICKEL ALLEY strategy: Fake it 'til you make it
2026-03-23T20:51:41Z•910820b1d2581e64fa076d1ee16a8bdcab8455d15a9ed88ba30bc5015c5f28b2
84 CVEsAndroidClickFixIranKeenaduMacSyncNICKEL ALLEYOperation Epic FuryPatch TuesdaySophos Firewall v22Workspace Protectionad fraudcritical vulnerabilitiescryptocurrency theftdeveloper-targetingfake companiesfirmware malwarehacktivisminfostealerinitial accessmacOSsocial engineering
What happened
A batch of Sophos X-Ops / Threat Research briefings covering multiple active risks: a NICKEL ALLEY campaign that lures software developers with fake companies, job offers and code repositories to steal cryptocurrency; Keenadu firmware-level malware preinstalled on some Android devices used primarily for ad fraud and providing persistent device control; evolving ClickFix social‑engineering campaigns increasingly targeting macOS users with infostealers (e.g., MacSync); analysis of preferred initial-access techniques used by Iran-linked groups and rising hacktivist activity tied to US–Israel–Iran
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 910820b1d2581e64fa076d1ee16a8bdcab8455d15a9ed88ba30bc5015c5f28b2
- Enrichment time
- 2026-03-23T20:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.