- What: Sophos reports on NICKEL ALLEY strategy involving malicious Python and Go malware
- Impact: Developers and IT teams may need to monitor for these threats
2026-03-23 (Back to Inventory) NICKEL ALLEY strategy: Fake it ‘til you make it Author(s): Sophos Counter Threat Unit Research Team Organization: Sophos py.pylangghost win.golangghost Open article directly Open article on Archive.org Related Articles 2025-12-05 ⋅ Sophos ⋅ Morgan Demboski Sharpening the knife: GOLD BLADE’s strategic evolution Earth Kapre 2025-08-26 ⋅ Sophos ⋅ Sophos Counter Threat Unit Research Team Velociraptor incident response tool abused for remote access 2025-01-25 ⋅ Sophos ⋅ Anthony Bradshaw , Colin Cowie , Daniel Souter , Hunter Neal , Mark Parsons , Sean Baird , Sean Gallagher Sophos MDR tracks two ransomware campaigns using “email bombing,” Microsoft Teams “vishing” ReedBed STAC5143 UNC4393