NICKEL ALLEY strategy: Fake it 'til you make it

2026-03-23T20:51:41Z910820b1d2581e64fa076d1ee16a8bdcab8455d15a9ed88ba30bc5015c5f28b2
84 CVEsAndroidClickFixIranKeenaduMacSyncNICKEL ALLEYOperation Epic FuryPatch TuesdaySophos Firewall v22Workspace Protectionad fraudcritical vulnerabilitiescryptocurrency theftdeveloper-targetingfake companiesfirmware malwarehacktivisminfostealerinitial accessmacOSsocial engineering

What happened

A batch of Sophos X-Ops / Threat Research briefings covering multiple active risks: a NICKEL ALLEY campaign that lures software developers with fake companies, job offers and code repositories to steal cryptocurrency; Keenadu firmware-level malware preinstalled on some Android devices used primarily for ad fraud and providing persistent device control; evolving ClickFix social‑engineering campaigns increasingly targeting macOS users with infostealers (e.g., MacSync); analysis of preferred initial-access techniques used by Iran-linked groups and rising hacktivist activity tied to US–Israel–Iran

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
910820b1d2581e64fa076d1ee16a8bdcab8455d15a9ed88ba30bc5015c5f28b2
Enrichment time
2026-03-23T20:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.