Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: other aliases, several other aliases, Jumpy Pisces, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, APT28, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Bronze Silhouette, DEV-0391, Turla, Snake, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, pink cocaine, wild ground phlox, the ALPHV Ransomware Group, ALPHV Blackcat, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34

Description

Pink first surfaced in the early 2020s and evolved into a ransomware-as-a-service (RaaS) model, now known by alias CL-CRI-1147. The group leverages a multi‑stage kill chain that begins with spearphishing emails containing ISO image attachments or Office documents replete with malicious macros and template injection payloads. Once inside the network, Pink deploys DLL side‑loading techniques to install TelePowerBot or KamiKakaBot backdoors, facilitating lateral movement and persistence via living‑off‑the‑land tools such as PowerShell, Windows Command Shell, and WMI. After establishing footholds, Pink exploits stolen credentials (often purchased from initial access brokers) or performs social engineering attacks that resemble a fake IT helpdesk to exfiltrate data from cloud services like SharePoint and OneDrive. The gang then executes double‑extortion tactics: they encrypt critical files using its own ransomware core while threatening to release the recovered data unless ransom demands are met—typically within a 72‑hour deadline. Pink also uses satellite internet links, notably Starlink, for command-and-control communications, further obfuscating their presence. The actors exploit publicly known vulnerabilities and widely available remote‑management tools, patching delays providing them a window to leverage known CVEs. Evidence points to an affiliation with The Com network—a conglomerate of English-speaking hackers and extortionists—though definitive attribution remains uncertain, leaving open the possibility that Pink may be state-sponsored or influenced by larger espionage groups such as MuddyWater.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Critical infrastructure
Education
Manufacturing
Media
Non profit
Energy
Aerospace
Aviation
Hospitality
Think tank
Pharmaceutical
Retail
Transportation
Gaming
Legal services
Information technology
Maritime
Utilities
Mining
Chemical
Nuclear
Entertainment
Oil gas
Construction

Targeted Countries / Regions

US
CN
RU
IR
VN
GB
IN
PK
UA
JP
IL
KP
KR
AU
SA
TW
AE
TR
BR
SG
DE
BY
MX
ES
PL
CA
RO
FR
NG
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Pink is an extortion group that has emerged as a ransomware-as-a-service platform, using sophisticated spearphishing, DLL side‑loading, and voice phishing to steal credentials and exfiltrate data before encrypting victim files. The gang frequently targets cloud storage such as SharePoint and OneDrive, threatens to leak compromised data within 72 hours, and demands payment for the ransom and the suppression of leaks. Pink operates alongside a loose network of English‑speaking hackers—often referred to as The Com—and has demonstrated an ability to pivot from initial access to sophisticated double‑extortion attacks against a broad range of sectors.

Goals & Targeting

Pink’s strategic objective centers on maximizing financial gain through double‑extortion while compromising a broad spectrum of high‑value industries. By stealing and exfiltrating data before encrypting, the group exploits both ransom payments and reputational damage. Target selection reflects an opportunistic approach: government agencies, critical infrastructure, financial institutions, telecommunications providers, healthcare networks, defense contractors, and various industrial sectors across dozens of countries—including the United States, Russia, Iran, China, India, Ukraine and many others—demonstrating a geographically diverse attack footprint aligned with lucrative data and payment ecosystems.

Enhanced Description

Key Capabilities

  • "Spearfishing emails with ISO image attachments"
  • "Template injection and malicious macros in Office documents"
  • "DLL side‑loading of malicious DLLs (TelePowerBot, KamiKakaBot)"
  • "Living‑off‑the‑land tactics including use of legitimate tools"
  • "Use of publicly available remote management software for lateral movement"
  • "Double extortion: data exfiltration before ransomware encryption"
  • "Credential theft and MFA bypass through social engineering or stolen accounts"
  • "Exploitation of known public vulnerabilities"
  • "Purchase of credentials from Initial Access Brokers"
  • "Command and control communications via satellite internet (Starlink)"
  • "Voice phishing and fake IT helpdesk impersonation"

MITRE ATT&CK Tactics

"Execution"
"Persistence"
"Defense Evasion"
"Discovery"
"Lateral Movement"
"Initial Access"
"Command and Control"
"Exfiltration"

ATT&CK Techniques

T1053.005
T1560.001
T1047
T1123
T1036.007
T1548.002
T1074.001
T1564
T1204.002
T1566.002
T1135
T1222.001
T1082
T1091
T1005
T1140
T1218
T1010
T1021
T1112
T1555.003
T1547.004
T1059
T1546
T1036.004
T1571
T1027
T1505
T1070.004
T1059.001
T1059.003
T1059.005
T1018

Software / Tooling

"TelePowerBot"
"KamiKakaBot"
"Pink Ransomware"
"Spearwing/Medusa"
"Custom Malware"

Campaigns & Victims

Pink operates on a rapid, opportunistic cadence—often delivering initial access via spearphishing or remote‑management software to gain footholds, then moving laterally using living‑off‑the‑land techniques before executing double‑extortion. The gang’s use of satellite C2 links like Starlink enables them to maintain communications outside typical corporate perimeter controls. Victims are typically large enterprises across a wide range of industries; the group leverages existing data exfiltration pathways, particularly from cloud platforms such as SharePoint and OneDrive, increasing leverage over compromised organizations. Notable operations include multiple high‑profile attacks reported in 2024–2026 where Pink threatened to release sensitive data following ransom negotiations, mirroring tactics employed by Lapsus$ and ShinyHunters.

IOC Patterns

  • "Spearfishing with ISO image attachments"
  • "Macro-based template injection in Office documents"
  • "DLL side‑loading indicators"
  • "Living-off-the-land tool usage patterns"
  • "Double extortion data exfiltration"
  • "Phishing campaign artifacts"
  • "Public vulnerability exploitation signatures"
  • "Credential purchase from Initial Access Broker indicators"
  • "Satellite internet command and control indications (Starlink)"

Recommended Actions

  • "Implement monitoring for emails containing ISO attachments and Office documents."
  • "Enforce macro disabling policies on endpoints."
  • "Deploy DLL side‑loading detection solutions."
  • "Maintain up‑to‑date patching to reduce exploitation of known vulnerabilities."
  • "Implement and continuously update phishing detection and user awareness training."
  • "Deploy vulnerability scanning and timely patching for public-facing applications."
  • "Monitor network traffic for unusual exfiltration patterns indicating double‑extortion activity."
  • "Detect and block command‑and‑control communications over commercial satellite links such as Starlink."
  • "Enforce least privilege and monitor for use of remote management tools beyond authorized limits."
  • "Require multi‑factor authentication across all user accounts and enforce strong password policies."

Suggested Tags

"APT"
"State-sponsored"
"Spearphishing"
"Template Injection"
"DLL Side-loading"
"Malicious Macro"
"Ransomware-as-a-Service"
"Double-Extortion"
"Living-off-the-Land"
"Phishing"
"Satellite-C2"
"Government Targeting"
"MuddyWater"

Confidence Assessment

Confidence in Pink’s tactical profile—such as spearphishing, DLL side‑loading, double extortion, and satellite C2—is medium to high due to corroborating reports from multiple reputable vendors. Attribution confidence remains moderate; overlapping aliases with other groups suggest potential collusion or shared infrastructure but concrete state sponsorship has not been conclusively proven. Significant gaps persist in the precise operational timeline (exact first appearance), full mapping of command-and-control infrastructure, ransom payment records, and definitive links to established espionage outfits.

ATT&CK Techniques

Command & Control
1 technique
Credential Access
1 technique
Initial Access
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 15 Filename 3 URL 1 IPv4 Address 1

References

  1. www.huntress.com — Cited by web research for: other aliases
  2. attack.mitre.org — Cited by web research for: Shell Crew
  3. www.group-ib.com — Cited by web research for: T1574.002
  4. www.group-ib.com — Cited by web research for: Spear-phishing
  5. attack.mitre.org — Cited by web research for: Pharmaceutical
  6. www.zscaler.com — Cited by web research for: RSOX

Intel Summary

40

Techniques

50

Tools

0

Campaigns

54

IOCs

0

Observed Data

12

Tactics

Tags

Ransomware
Critical Infrastructure
Phishing
"APT"
"State-sponsored"
"Spearphishing"
"Template Injection"
"DLL Side-loading"
"Malicious Macro"
"Ransomware-as-a-Service"
"Double-Extortion"
"Living-off-the-Land"
"Phishing"
"Satellite-C2"
"Government Targeting"
"MuddyWater"

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
55%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.