Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DarkPink

Also known as: Saaiwc, tracked as, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, ALPHV, Play, Vice Society, Black Basta, Royal.Ransomware ecosystem, Saaiwc Group, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, Royal Ransomware

Description

DarkPink is an APT-level actor whose operations revolve around highly tailored malware combined with conventional delivery vectors. Their primary vector remains spear‑phishing via ISO images or malicious PDFs that host custom Trojans, enabling credential theft and lateral movement within target networks. Post‑infection, the group exploits public-facing vulnerabilities (notably CVE-2023‑38831) to expand foothold and deploy persistence mechanisms such as DLL side‑loading and scheduled tasks.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Telecommunications
Healthcare
Education
Media
Manufacturing
Non profit
Critical infrastructure
Energy
Retail
Information technology
Aviation
Hospitality
Pharmaceutical
Aerospace
Transportation
Think tank
Gaming
Maritime
Mining
Chemical
Legal services
Nuclear
Construction
Entertainment
Oil gas
Utilities
Food agriculture

Targeted Countries / Regions

US
CN
RU
UA
VN
GB
IR
DE
PL
IL
AU
IN
PK
JP
TW
ES
KP
SA
FR
AE
SG
BY
KR
CA
TR
MX
NL
RO
NG
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 11 hours ago

Executive Summary

DarkPink (Saaiwc) is an advanced threat active since mid‑2021 that specializes in spear‑phishing delivery of custom trojans such as TelePowerBot and KamiKakaBot to government, military and related organizations across Southeast Asia and Europe. The group leverages public cloud services for command‑and‑control, exfiltration, and persistence while exploiting known vulnerabilities (e.g., CVE-2023‑38831) and maintaining a low profile through DLL side‑loading and scheduled tasks.

Goals & Targeting

The actor’s strategic aims are centered on financial gain through ransomware or data exfiltration while preserving operational stealth. DarkPink deliberately targets nation‑state, defense, non‑profit, and critical infrastructure entities in the Asia‑Pacific and European regions, thereby maximizing political leverage and value of compromised data. Their persistent use of cloud platforms and third‑party web services indicates a focus on obscuring signal paths and scaling operations without raising immediate alarms.

Enhanced Description

Key Capabilities

  • Deployment of custom trojan malware (TelePowerBot, KamiKakaBot) via spear‑phishing with ISO images or PDFs
  • Use of phishing & social engineering including spam overload tactics to compromise help‑desk accounts
  • Exploitation of public-facing vulnerabilities such as CVE-2023‑38831 for privilege escalation and persistence
  • Persistence through DLL side‑loading and scheduled tasks
  • Leveraging compromised cloud accounts (Dropbox, OneDrive, AWS S3) for staging, exfiltration, and uploader functionality
  • Abuse of third‑party web services (Google, GitHub, Twitter, SendGrid) as command‑and‑control or infrastructure
  • Installation of backdoored container images (AWS AMI, GCP image, Azure Image, Docker registry) for persistent foothold
  • Multiple kill‑chain stages covering initial access to exfiltration with stealthy operations

MITRE ATT&CK Tactics

Initial Access
Execution
Discovery
Privilege Escalation
Defense Evasion
Persistence
Command and Control
Exfiltration
Lateral Movement

ATT&CK Techniques

T1071.003
T1566
T1037
T1557
T1583
T1123
T1133
T1547
T1119
T1115
T1082
T1071
T1140
T1190
T1567
T1620
T1010
T1560
T1185
T1580
T1217
T1595
T1548
T1087
T1059
T1020
T1083
T1612
T1657
T1057
T1098
T1048
T1110
T1531
T1027
T1486
T1671
T1197
T1650
T1651
T1134
T1027.002

Software / Tooling

Custom Tools
Akira
Royal
PowerSploit
Mythic
PowerShell
Dark
LockBit
Conti
Hive
Pink
Tsunami
KamiKakaBot
Kimsuky
Lynx
PLAY
TelePowerBot
Void
BlackByte

Campaigns & Victims

DarkPink’s campaigns usually commence with a sophisticated phishing push, distributing ISO or PDF attachments that infect the target. The group then pivots to exploitation of known CVE‑2023‑38831 and other weak points to solidify persistence via DLL side‑loading and scheduled tasks. They frequently move data through compromised cloud storage accounts and funnel exfiltration traffic over public services such as Google Drive or GitHub, enabling rapid dissemination while maintaining low detection risk. The actor has demonstrated flexibility in using both on‑premise infrastructure and cloud‑based backdoors, indicating high operational tempo and adaptability.

IOC Patterns

  • Public cloud service domains for C2 and exfiltration (Google Drive, GitHub, Dropbox)
  • Malicious PDF/ISO file hashes delivered via spear‑phishing
  • Suspicious executable files such as cmd.exe, explorer.exe, user32.dll, system.bat
  • Temporary domain names used for command & control or data staging (e.g., TEMP.Veles)

Recommended Actions

  • Implement strict outbound monitoring for traffic to third‑party services and alert on anomalous API calls to Google, GitHub, and Twitter.
  • Enforce multi‑factor authentication for all help‑desk and remote support accounts to mitigate spam overload phishing.
  • Patch systems promptly against CVE-2023‑38831 and other known vulnerabilities to block exploitation vectors.
  • Monitor Windows event logs for DLL side‑loading and scheduled task creation indicative of persistence installation.
  • Segment and secure cloud storage accounts; enforce least‑privilege access policies on Dropbox, OneDrive, and AWS S3.
  • Deploy endpoint detection that flags the execution of custom trojans (TelePowerBot, KamiKakaBot) and obfuscated binaries.
  • Conduct phishing awareness training focused on ISO/payload attachments and suspicious email domains.

Suggested Tags

DarkPink
Saaiwc
APT
GovernmentTargeting
MilitaryTargeting
AsiaPacific
Europe
CommandAndControlViaWebServices
Phishing
InitialAccess
CustomMalware
FinancialGain
Stealth
AdvancedPersistentThreat

Confidence Assessment

The intelligence indicates a moderately high confidence in DarkPink’s attribution, supported by multiple independent sources and consistent TTP patterns. However, gaps remain regarding precise operational timelines, full scope of infrastructure, and definitive linkage to specific financial outcomes or ransomware payloads.

ATT&CK Techniques

Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 18 Filename 2

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. attack.mitre.org — Cited by web research for: services
  3. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  4. cert.europa.eu — Cited by web research for: ALPHV
  5. www.group-ib.com — Cited by web research for: PowerShell
  6. learn.microsoft.com — Cited by web research for: Tsunami
  7. https://www.group-ib.com/blog/dark-pink-episode-2/ — Cited by AI analysis.
  8. https://therecord.media/dark-pink- — Cited by AI analysis.

Intel Summary

42

Techniques

42

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
Critical Infrastructure
Phishing
Government Targeting
espionage
government
military
Southeast_Asia
Europe
DarkPink
Saaiwc
GovernmentTargeting
MilitaryTargeting
AsiaPacific
CommandAndControlViaWebServices
InitialAccess
CustomMalware
FinancialGain
Stealth
AdvancedPersistentThreat

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.