Also known as: other aliases, several other aliases, Jumpy Pisces, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, APT28, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Bronze Silhouette, DEV-0391, Turla, Snake, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, pink cocaine, wild ground phlox, the ALPHV Ransomware Group, ALPHV Blackcat, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34
Pink first surfaced in the early 2020s and evolved into a ransomware-as-a-service (RaaS) model, now known by alias CL-CRI-1147. The group leverages a multi‑stage kill chain that begins with spearphishing emails containing ISO image attachments or Office documents replete with malicious macros and template injection payloads. Once inside the network, Pink deploys DLL side‑loading techniques to install TelePowerBot or KamiKakaBot backdoors, facilitating lateral movement and persistence via living‑off‑the‑land tools such as PowerShell, Windows Command Shell, and WMI. After establishing footholds, Pink exploits stolen credentials (often purchased from initial access brokers) or performs social engineering attacks that resemble a fake IT helpdesk to exfiltrate data from cloud services like SharePoint and OneDrive. The gang then executes double‑extortion tactics: they encrypt critical files using its own ransomware core while threatening to release the recovered data unless ransom demands are met—typically within a 72‑hour deadline. Pink also uses satellite internet links, notably Starlink, for command-and-control communications, further obfuscating their presence. The actors exploit publicly known vulnerabilities and widely available remote‑management tools, patching delays providing them a window to leverage known CVEs. Evidence points to an affiliation with The Com network—a conglomerate of English-speaking hackers and extortionists—though definitive attribution remains uncertain, leaving open the possibility that Pink may be state-sponsored or influenced by larger espionage groups such as MuddyWater.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Pink is an extortion group that has emerged as a ransomware-as-a-service platform, using sophisticated spearphishing, DLL side‑loading, and voice phishing to steal credentials and exfiltrate data before encrypting victim files. The gang frequently targets cloud storage such as SharePoint and OneDrive, threatens to leak compromised data within 72 hours, and demands payment for the ransom and the suppression of leaks. Pink operates alongside a loose network of English‑speaking hackers—often referred to as The Com—and has demonstrated an ability to pivot from initial access to sophisticated double‑extortion attacks against a broad range of sectors.
Goals & Targeting
Pink’s strategic objective centers on maximizing financial gain through double‑extortion while compromising a broad spectrum of high‑value industries. By stealing and exfiltrating data before encrypting, the group exploits both ransom payments and reputational damage. Target selection reflects an opportunistic approach: government agencies, critical infrastructure, financial institutions, telecommunications providers, healthcare networks, defense contractors, and various industrial sectors across dozens of countries—including the United States, Russia, Iran, China, India, Ukraine and many others—demonstrating a geographically diverse attack footprint aligned with lucrative data and payment ecosystems.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Pink operates on a rapid, opportunistic cadence—often delivering initial access via spearphishing or remote‑management software to gain footholds, then moving laterally using living‑off‑the‑land techniques before executing double‑extortion. The gang’s use of satellite C2 links like Starlink enables them to maintain communications outside typical corporate perimeter controls. Victims are typically large enterprises across a wide range of industries; the group leverages existing data exfiltration pathways, particularly from cloud platforms such as SharePoint and OneDrive, increasing leverage over compromised organizations. Notable operations include multiple high‑profile attacks reported in 2024–2026 where Pink threatened to release sensitive data following ransom negotiations, mirroring tactics employed by Lapsus$ and ShinyHunters.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Pink’s tactical profile—such as spearphishing, DLL side‑loading, double extortion, and satellite C2—is medium to high due to corroborating reports from multiple reputable vendors. Attribution confidence remains moderate; overlapping aliases with other groups suggest potential collusion or shared infrastructure but concrete state sponsorship has not been conclusively proven. Significant gaps persist in the precise operational timeline (exact first appearance), full mapping of command-and-control infrastructure, ransom payment records, and definitive links to established espionage outfits.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
50
Tools
0
Campaigns
54
IOCs
0
Observed Data
12
Tactics