Also known as: tracked as, the Newscaster Team, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, CVE-2026-3502, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork
Nickel Alley operates primarily through sophisticated social engineering campaigns targeting tech professionals, government agencies, defense contractors, and diplomatic missions. They distribute fake job offers and counterfeit LinkedIn/GitHub profiles that host malware repositories. Leveraging the ClickFix tactic, the group prompts victims to execute local commands which trigger downloads of custom RATs such as PyLangGhost, enabling file exfiltration and system profiling—including targeting Chrome cryptocurrency wallet data. The threat actor also exploits known vulnerabilities like CVE‑2015‑1701 via spear‑phishing attachments on malicious Microsoft Word documents. More recently they have leveraged a zero‑day (CVE‑2026‑3502) in the TrueConf client to distribute arbitrary payloads from an attacker‑controlled server, resulting in remote code execution across all connected endpoints. Nickel Alley’s dual focus spans both financial (cryptocurrency theft) and strategic sectors, with campaigns designed to infiltrate supply chains, compromise corporate information systems, and extract valuable classified material. Their modus operandi demonstrates a combination of early‑stage infiltration through user‑execution prompts and persistent lateral movement facilitated by RAT and backdoor families.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Nickel Alley is a North Korean threat group that blends social engineering with technical exploitation to compromise technology and diplomatic personnel worldwide. Their operations focus on phishing, fake developer tools (ClickFix), and supply‑chain attacks, enabling them to steal sensitive data and install RATs such as PyLangGhost. The group’s recent activity highlights use of a zero‑day in TrueConf and CVE‑2015‑1701 to further expand its reach.
Goals & Targeting
The group’s strategic objectives center on espionage and data exfiltration from high‑value technology and defense targets. By recruiting or tricking professionals in the tech sector, Nickel Alley gains privileged access to proprietary software, code repositories, and network infrastructure. The exploitation of zero‑day vulnerabilities further indicates a pattern aimed at expanding their foothold within targeted organizations, enabling both covert surveillance and potential disruption.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Nickel Alley’s campaigns exhibit a measured tempo, typically deploying spear‑phishing chains that culminate in the delivery of IRONHALO or ELMER backdoors. Their operations frequently target governmental and defense organizations, but they also extend to commercial technology firms via fake job postings and compromised code repositories. Notable past attacks include the 2015 CVE-2015-1701 exploitation through malicious Word documents, as well as the recent TrueConf CVE‑2026‑3502 supply‑chain compromise that leveraged a rogue on‑premises server. The group often mixes technical exploitation with deceptive social engineering to maintain persistence and conceal lateral movement.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the core capabilities and techniques is moderate, as multiple independent sources corroborate spear‑phishing, CVE exploitation, and ClickFix usage. However, gaps remain regarding the exact timelines, full scope of operations, and comprehensive toolset, limiting a definitive assessment of their current operational tempo.
No campaigns linked yet.
No observed data linked yet.
6
Techniques
46
Tools
0
Campaigns
32
IOCs
0
Observed Data
4
Tactics