🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Global
DARK PINK

/actor/dark-pink/  ·  0 intel reports

Year Established
2021
Attribution
Unknown (Southeast Asian Suspected)
Motivation
Espionage
Modus Operandi (MO)
Spear-phishing, USB-based propagation, government and military targeting in ASEAN region
Primary Aliases
Saaiwc Group, TNG (The Noodle Group)

Dark Pink is an advanced persistent threat group identified by researchers at Group-IB in 2023, conducting targeted cyber espionage campaigns against government ministries, military organisations, and non-governmental organisations across Southeast Asia and Europe. The group is believed to have been active since at least 2021 but remained largely undetected until systematic analysis of attack patterns revealed a previously undocumented threat actor.

Dark Pink's attack chain is notable for its multi-stage sophistication: initial compromise typically occurs through highly targeted spear-phishing emails containing malicious ISO image files, which upon mounting deliver the group's custom malware framework. A particularly distinctive capability is the group's USB propagation module , malware that spreads to connected USB drives to enable lateral movement into air-gapped or network-isolated environments, a technique reflecting targeted espionage against government facilities with physical security controls.

The group deploys a custom toolset including TelePowerBot (which uses Telegram for command-and-control), KamiKakaBot (a .NET-based backdoor), and Cucky/Ctealer information stealers designed to extract browser credentials and session tokens. Their use of legitimate messaging platforms for C2 represents a sophisticated approach to evading network-based detection tools that blocklist known malicious domains.

Dark Pink's confirmed victims span military bodies and government ministries in the Philippines, Malaysia, Cambodia, Indonesia, and Bosnia and Herzegovina, as well as a European government development agency. The breadth of the targeting, combined with the technical sophistication of their toolset, suggests a well-resourced group with a clear strategic intelligence mandate covering ASEAN political and military affairs.

Cyber Espionage Tactics and Persistence Mechanisms: Operational tracking indicates that Dark Pink executes long-term cyber espionage campaigns aligned with strategic intelligence requirements. The threat group weaponizes spear-phishing lures with malicious Office attachments, exploits unpatched edge appliances and VPN gateways, and establishes covert command-and-control (C2) channels using custom backdoors and legitimate administrative binaries. Defending against these advanced persistent threats requires comprehensive endpoint detection and response (EDR) visibility, continuous credential auditing, and proactive threat hunting across sensitive network enclaves.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles