New Dark Pink APT Group Attacks the Government Bodies and Militaries in Asia-Pacific
Dark Pink is an advanced persistent threat (APT) group that uses spear phishing techniques to target various entities across Asia-Pacific and Europe.
Between June and December 2022, a group called Dark Pink launched numerous APTs. There were attacks against a number of Asian countries, including Vietnam, Cambodia, Indonesia, the Philippines, and Malaysia. Bosnia and Herzegovina, a country in Europe, was also attacked.
“Group-IB’s early research into Dark Pink has revealed that these threat actors are leveraging a new set of tactics, techniques, and procedures rarely utilized by previously known APT groups. They leverage a custom toolkit, featuring TelePowerBot, KamiKakaBot, and Cucky and Ctealer information stealers (all names dubbed by Group-IB) with the aim of stealing confidential documentation held on the networks of government and military organizations,” said a Group-IB Malware Analyst.
According to reports, the initial vector of Dark Pink’s attacks was spear phishing campaigns, where the operators would impersonate job applicants. Dark Pink can also infect USB devices connected to infected computers. Additionally, it has the ability to access the messengers installed on compromised computers.
The security team informed that the threat actors had also created PowerShell scripts to communicate between victims and their infrastructure, and they used Telegram API to communicate with infected infrastructure.
“Countries of the Asia-Pacific region have long been the target of advanced persistent threat (APT) groups. Earlier Group-IB research found that this region has often been a “key arena” of APT activity, and a mixture of nation-state threat actors from China, North Korea, Iran, and Pakistan have been tied to a wave of attacks in the region. More often than not, the primary motive for APT attacks in the Asia-Pacific (APAC) region is not financial gain, but rather espionage,” Group-IB officials figured out.
In their research report (published on January 2023), the Group-IB security analysts informed that the Dark Pink APT group and the threats are still active. The officials are investing the issue further to determine its scope. They suggested organizations take the precautions mentioned below to prevent hacking:
- Use business email protection tools.
- Introduce a cybersecurity culture in the workspace.
- Limit file-sharing access to confidential resources.
- Only use trustworthy tools with good reputations to get things done.
Leave a Comment
Cancel