Also known as: Saaiwc, tracked as, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, ALPHV, Play, Vice Society, Black Basta, Royal.Ransomware ecosystem, Saaiwc Group, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, Royal Ransomware
DarkPink is an APT-level actor whose operations revolve around highly tailored malware combined with conventional delivery vectors. Their primary vector remains spear‑phishing via ISO images or malicious PDFs that host custom Trojans, enabling credential theft and lateral movement within target networks. Post‑infection, the group exploits public-facing vulnerabilities (notably CVE-2023‑38831) to expand foothold and deploy persistence mechanisms such as DLL side‑loading and scheduled tasks.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
DarkPink (Saaiwc) is an advanced threat active since mid‑2021 that specializes in spear‑phishing delivery of custom trojans such as TelePowerBot and KamiKakaBot to government, military and related organizations across Southeast Asia and Europe. The group leverages public cloud services for command‑and‑control, exfiltration, and persistence while exploiting known vulnerabilities (e.g., CVE-2023‑38831) and maintaining a low profile through DLL side‑loading and scheduled tasks.
Goals & Targeting
The actor’s strategic aims are centered on financial gain through ransomware or data exfiltration while preserving operational stealth. DarkPink deliberately targets nation‑state, defense, non‑profit, and critical infrastructure entities in the Asia‑Pacific and European regions, thereby maximizing political leverage and value of compromised data. Their persistent use of cloud platforms and third‑party web services indicates a focus on obscuring signal paths and scaling operations without raising immediate alarms.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DarkPink’s campaigns usually commence with a sophisticated phishing push, distributing ISO or PDF attachments that infect the target. The group then pivots to exploitation of known CVE‑2023‑38831 and other weak points to solidify persistence via DLL side‑loading and scheduled tasks. They frequently move data through compromised cloud storage accounts and funnel exfiltration traffic over public services such as Google Drive or GitHub, enabling rapid dissemination while maintaining low detection risk. The actor has demonstrated flexibility in using both on‑premise infrastructure and cloud‑based backdoors, indicating high operational tempo and adaptability.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence indicates a moderately high confidence in DarkPink’s attribution, supported by multiple independent sources and consistent TTP patterns. However, gaps remain regarding precise operational timelines, full scope of infrastructure, and definitive linkage to specific financial outcomes or ransomware payloads.
No campaigns linked yet.
No observed data linked yet.
42
Techniques
42
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics