TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

IT Pro

North Korean hackers are duping freelance developers with fake interviews to steal cryptocurrency and deliver malware — Sophos warns the 'Nickel Alley' group is using LinkedIn, Upwork, and Fiverr to target victims

Emma Woollacott · 2026-04-29 · Read original ↗

ATT&CK techniques detected

5 predictions
T1566.002Spearphishing Link
97%
“nickel alley, a threat group operating on behalf of the north korean government. " the group notoriously targets professionals in the technology sector by advertising fake job opportunities, deceiving prospective candidates through a fake job interview process, and ultimately del…”
T1195.001Compromise Software Dependencies and Development Tools
74%
“forbes, raconteur and specialist technology titles. - liz kendall : uk has to act fast to secure ai leadership news tech secretary liz kendall has pledged greater investment in the chip and semiconductor technologies that underpin ai - amazon cto werner vogels on the future of so…”
T1204.002Malicious File
47%
“actors hadn ' t actually built the website at the time the emails were sent, meaning that the site simply displayed the hosting provider ’ s default page. over the last year, the group has used the popular clickfix tactic to deliver pylangghost rat malware via fake job skills ass…”
T1588.002Tool
40%
“‘ makes for a good headline ’, but cyber crime activities peak later in life news with family responsibilities and mortgages to pay, it ' s not teenagers dishing out malware or carrying out cyber extortion - cloudflare warns state - backed hackers are ‘ weaponizing legitimate ent…”
T1588.002Tool
33%
“north korean hackers are duping freelance developers with fake interviews to steal cryptocurrency and deliver malware — sophos warns the ' nickel alley ' group is using linkedin, upwork, and fiverr to target victims north korean hackers are duping freelance developers with fake i…”

Summary

A fake interview process uses coding tests and repo downloads to deliver malware