logo

Dark Pink

ID: 3d0f9c63-7a31-52bd-96d8-4c1f685d242a

STIX ID: report--3d0f9c63-7a31-52bd-96d8-4c1f685d242a

Feed Name: Group-IB Blog

Threat Score
90/100

Date Published: 2023-01-11

Date Updated: 2026-04-27

...
...

Group-IB describes “Dark Pink,” a newly identified APT conducting targeted espionage across APAC (and one European target) from mid‑2021 through late 2022. The actors used tailored spear‑phishing with ISO attachments, DLL side‑loading and an uncommon Event Triggered Execution (file association) technique to deploy custom tools (TelePowerBot, KamiKakaBot) and steal data via Telegram, Dropbox and email; they also deployed stealers (Cucky, Ctealer), recorded microphone audio, and propagated via USB and network shares. The report provides technical analysis, kill chains, IOCs (hashes, registry keys, paths, exfiltration emails) and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.