NICKEL ALLEY strategy: Fake it 'til you make it
2026-03-24T08:51:38Z•e5fb788e618b8b5f8ba6645caeac48a8c348ab8fed827503937cf5618e7867c6
AndroidCISOCVECVE-2026-21992ClickFixIranKeenaduNICKEL ALLEYNorth KoreaOraclePatch Tuesdayad fraudcryptocurrency theftfirmware malwarehacktivisminfostealerinitial accessmacOSsocial engineeringsoftware supply chainvulnerability
What happened
Feed highlights multiple active threats and notable vulnerabilities: a Sophos analysis of the NICKEL ALLEY campaign shows threat actors using fake companies, job offers and code repositories to target software developers and steal cryptocurrency (attributed to North Korea). Android devices have been observed shipping with firmware-level Keenadu malware that grants persistent control and is being used for ad fraud. Sophos published an advisory on Oracle vulnerability CVE-2026-21992 affecting core products. Reports describe initial-access techniques favored by Iran-linked groups, increased macOS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- e5fb788e618b8b5f8ba6645caeac48a8c348ab8fed827503937cf5618e7867c6
- Enrichment time
- 2026-03-24T08:51:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.