Dark Pink
ID: 3d0f9c63-7a31-52bd-96d8-4c1f685d242a
STIX ID: report--3d0f9c63-7a31-52bd-96d8-4c1f685d242a
Feed Name: Group-IB Blog
Group-IB describes “Dark Pink,” a newly identified APT conducting targeted espionage across APAC (and one European target) from mid‑2021 through late 2022. The actors used tailored spear‑phishing with ISO attachments, DLL side‑loading and an uncommon Event Triggered Execution (file association) technique to deploy custom tools (TelePowerBot, KamiKakaBot) and steal data via Telegram, Dropbox and email; they also deployed stealers (Cucky, Ctealer), recorded microphone audio, and propagated via USB and network shares. The report provides technical analysis, kill chains, IOCs (hashes, registry keys, paths, exfiltration emails) and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
