> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
DARK PINK
/actor/dark-pink/ · 0 intel reports
Dark Pink is an advanced persistent threat group identified by researchers at Group-IB in 2023, conducting targeted cyber espionage campaigns against government ministries, military organisations, and non-governmental organisations across Southeast Asia and Europe. The group is believed to have been active since at least 2021 but remained largely undetected until systematic analysis of attack patterns revealed a previously undocumented threat actor.
Dark Pink's attack chain is notable for its multi-stage sophistication: initial compromise typically occurs through highly targeted spear-phishing emails containing malicious ISO image files, which upon mounting deliver the group's custom malware framework. A particularly distinctive capability is the group's USB propagation module , malware that spreads to connected USB drives to enable lateral movement into air-gapped or network-isolated environments, a technique reflecting targeted espionage against government facilities with physical security controls.
The group deploys a custom toolset including TelePowerBot (which uses Telegram for command-and-control), KamiKakaBot (a .NET-based backdoor), and Cucky/Ctealer information stealers designed to extract browser credentials and session tokens. Their use of legitimate messaging platforms for C2 represents a sophisticated approach to evading network-based detection tools that blocklist known malicious domains.
Dark Pink's confirmed victims span military bodies and government ministries in the Philippines, Malaysia, Cambodia, Indonesia, and Bosnia and Herzegovina, as well as a European government development agency. The breadth of the targeting, combined with the technical sophistication of their toolset, suggests a well-resourced group with a clear strategic intelligence mandate covering ASEAN political and military affairs.
Cyber Espionage Tactics and Persistence Mechanisms: Operational tracking indicates that Dark Pink executes long-term cyber espionage campaigns aligned with strategic intelligence requirements. The threat group weaponizes spear-phishing lures with malicious Office attachments, exploits unpatched edge appliances and VPN gateways, and establishes covert command-and-control (C2) channels using custom backdoors and legitimate administrative binaries. Defending against these advanced persistent threats requires comprehensive endpoint detection and response (EDR) visibility, continuous credential auditing, and proactive threat hunting across sensitive network enclaves.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.