Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Nickel Alley

Also known as: tracked as, the Newscaster Team, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, CVE-2026-3502, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork

Description

Nickel Alley operates primarily through sophisticated social engineering campaigns targeting tech professionals, government agencies, defense contractors, and diplomatic missions. They distribute fake job offers and counterfeit LinkedIn/GitHub profiles that host malware repositories. Leveraging the ClickFix tactic, the group prompts victims to execute local commands which trigger downloads of custom RATs such as PyLangGhost, enabling file exfiltration and system profiling—including targeting Chrome cryptocurrency wallet data. The threat actor also exploits known vulnerabilities like CVE‑2015‑1701 via spear‑phishing attachments on malicious Microsoft Word documents. More recently they have leveraged a zero‑day (CVE‑2026‑3502) in the TrueConf client to distribute arbitrary payloads from an attacker‑controlled server, resulting in remote code execution across all connected endpoints. Nickel Alley’s dual focus spans both financial (cryptocurrency theft) and strategic sectors, with campaigns designed to infiltrate supply chains, compromise corporate information systems, and extract valuable classified material. Their modus operandi demonstrates a combination of early‑stage infiltration through user‑execution prompts and persistent lateral movement facilitated by RAT and backdoor families.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Energy
Telecommunications
Aerospace
Media
Education
Information technology
Maritime
Manufacturing
Think tank
Healthcare
Pharmaceutical
Chemical
Mining
Hospitality
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
GB
IN
JP
DE
KR
IR
RU
SA
TW
FR
CA
IL
TR
AU
KZ
PK
UA
VN
PL
KP
AE
SG
NL
BR
ES
IQ
MX
BY
IT
SY
RO
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 6 hours ago

Executive Summary

Nickel Alley is a North Korean threat group that blends social engineering with technical exploitation to compromise technology and diplomatic personnel worldwide. Their operations focus on phishing, fake developer tools (ClickFix), and supply‑chain attacks, enabling them to steal sensitive data and install RATs such as PyLangGhost. The group’s recent activity highlights use of a zero‑day in TrueConf and CVE‑2015‑1701 to further expand its reach.

Goals & Targeting

The group’s strategic objectives center on espionage and data exfiltration from high‑value technology and defense targets. By recruiting or tricking professionals in the tech sector, Nickel Alley gains privileged access to proprietary software, code repositories, and network infrastructure. The exploitation of zero‑day vulnerabilities further indicates a pattern aimed at expanding their foothold within targeted organizations, enabling both covert surveillance and potential disruption.

Enhanced Description

Key Capabilities

  • Spear‑phishing via malicious Word documents (CVE-2015-1701)
  • Watering hole attacks
  • Supply‑chain attacks
  • Exploitation of known and zero‑day vulnerabilities
  • Custom downloader IRONHALO and backdoor ELMER delivery
  • Fake developer tool tactics including ClickFix-style prompts to run local commands
  • Distribute and execute arbitrary files via compromised TrueConf updater mechanism
  • Remote code execution on endpoints controlled by attacker‑controlled on‑premises TrueConf server

MITRE ATT&CK Tactics

Initial Access
Execution
Privilege Escalation

ATT&CK Techniques

T1566.001
T1189
T1195
T1068
T1204.004
T1105

Software / Tooling

IRONHALO
ELMER
ClickFix
PyLangGhost RAT
TrueConf

Campaigns & Victims

Nickel Alley’s campaigns exhibit a measured tempo, typically deploying spear‑phishing chains that culminate in the delivery of IRONHALO or ELMER backdoors. Their operations frequently target governmental and defense organizations, but they also extend to commercial technology firms via fake job postings and compromised code repositories. Notable past attacks include the 2015 CVE-2015-1701 exploitation through malicious Word documents, as well as the recent TrueConf CVE‑2026‑3502 supply‑chain compromise that leveraged a rogue on‑premises server. The group often mixes technical exploitation with deceptive social engineering to maintain persistence and conceal lateral movement.

IOC Patterns

  • domain
  • file

Recommended Actions

  • Monitor for malicious Word document attachments and CVE-2015-1701 usage in phishing campaigns
  • Implement strict controls against fake developer tool prompts (e.g., ClickFix) by disabling automatic run of prompts from untrusted sources
  • Patch known vulnerabilities promptly, including CVE‑2026‑3502 in TrueConf and CVE‑2015‑1701 in Office products
  • Review source-code repositories and CI/CD secrets for unauthorized changes and malicious code injection
  • Deploy network monitoring to detect anomalous outbound connections to suspicious domains such as demo-cloud.space or temp.hermit
  • Segment and isolate true-communication servers (e.g., TrueConf) from the rest of the corporate network until the zero‑day is fully mitigated

Suggested Tags

APT
Spearphishing
WateringHole
SupplyChainAttack
ZeroDayExploitation
DeveloperToolSpoofing
ClickFix
NickelAlley
PyLangGhostRAT
IRONHALO
ELMER
TrueConf
CVE-2026-3502
RemoteCodeExecution

Confidence Assessment

The confidence in the core capabilities and techniques is moderate, as multiple independent sources corroborate spear‑phishing, CVE exploitation, and ClickFix usage. However, gaps remain regarding the exact timelines, full scope of operations, and comprehensive toolset, limiting a definitive assessment of their current operational tempo.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

Intel Summary

6

Techniques

46

Tools

0

Campaigns

32

IOCs

0

Observed Data

4

Tactics

Tags

APT
Financial Targeting
Critical Infrastructure
Supply Chain Attack
North Korea
Supply Chain Compromise
Cryptocurrency Theft
Spearphishing
WateringHole
SupplyChainAttack
ZeroDayExploitation
DeveloperToolSpoofing
ClickFix
NickelAlley
PyLangGhostRAT
IRONHALO
ELMER
TrueConf
CVE-2026-3502
RemoteCodeExecution

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.