logo

Pink is the latest goon squad to use fake helpdesk calls to steal creds

ID: 3043086a-7b6f-57f6-87d8-587b7546ab78

STIX ID: report--3043086a-7b6f-57f6-87d8-587b7546ab78

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

...
...

Pink is an extortion group using vishing and fake help-desk calls to phish credentials and bypass MFA, then exfiltrate sensitive cloud-stored data (SharePoint, OneDrive) to extort organizations; Unit 42 and Google Threat Intelligence link the operation to previous brands/actors (e.g., BlackFile/UNC6671, The Com) and published IoCs including phishing domains (passkeyadd.com, passkeydeploy.com, deploypasskey.com), three IP addresses, and observed user-agent strings to aid defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.