Cyberint, the threat intelligence firm whose analysts scour the deep and dark web, has identified a newly active group named Dark Pink launching advanced persistent threat (APT) attacks across various sectors, including government agencies in the Asia Pacific (APAC) region in recent months.
Dark Pink, also known as the Saaiwc Group, initiated its attacks around mid-2021, but its heightened activity emerged more prominently in late 2022, as observed by Cyberint. It is also suspected to have originated in Vietnam.
“The main objectives of Dark Pink include corporate espionage and document theft to capture audio through compromised device microphones and exfiltrating data from messaging platforms,” Adi Bleih, security researcher at Cyberint, told Back End News in an email interview.
Kaspersky: APT campaign attacks via Safari browser
Kaspersky discovers emerging APT threat actor in APAC
According to Cyberint, Dark Pink primarily targets the Asia-Pacific (APAC) region with affected countries Brunei, Cambodia, Indonesia, Malaysia, Philippines, Thailand, and Vietnam. The group branched out its attacks to European nations including Bosnia and Herzegovina, where they expanded their scope to target a governmental ministry.
Cyberint has confirmed that there are government agencies across the region, including the Philippines, that have been targeted by Dark Pink. Even nongovernmental organizations and religious organizations didn’t escape the attacks of the APT groups.
Types of attacks
Bleih detailed Dark Pink’s methods, citing their use of various tactics, techniques, and procedures (TTPs) in cyber-attacks. The group employs diverse techniques for data exfiltration, including email, public cloud services like Dropbox, and recently, the exploitation of the HTTP protocol and a Webhook service.
“Dark Pink relies on spear-phishing emails containing shortened URLs leading to a free-file-sharing site,” Bleih said. “Victims are presented with the option to download an ISO image, which contains files for infecting victim networks.”
The group utilizes custom malware tools such as TelePowerBot and KamiKakaBot, embedded within ISO images and distributed through spear-phishing campaigns.
TelePowerBot, a registry implant activated during system boot via a script, establishes a connection with a Telegram channel, awaiting PowerShell commands for device control and data harvesting.
KamiKakaBot, a .NET version of TelePowerBot, enhances espionage capabilities by extracting confidential information from compromised systems. Both tools, alongside Cucky and Ctealer, information stealers coded in .NET and C/C++, respectively, form part of Dark Pink’s specialized toolkit.
APT groups
Cyberint revealed Dark Pink’s association with a GitHub account where PowerShell scripts, ZIP archives, and custom malware are stored for potential future deployment on targeted devices. This indicates the group’s use of the platform to store and potentially share malicious tools and scripts for future attacks.
“These tactics showcase the complexity and adaptability of Dark Pink campaigns, with the group creating tools in various programming languages to compromise defense infrastructure and establish a lasting presence on their targets’ networks,” Bleih said.
Cyberint’s surveillance revealed potential links between Dark Pink and OCEAN BUFFALO group, also known as APT32, OceanLotus, or SeaLotus, an active Vietnam-based targeted group since at least 2012.
Security challenges
Bleih highlighted the challenges posed by emerging threat groups like Dark Pink, emphasizing the need for a coordinated global security response to combat evolving and diverse threats.
“Geopolitical motivations behind such groups could lead to complex attack styles and tensions between nations,” he said.
The heightened risks underscore the necessity for organizations to continually adapt their defenses. Cyberint warns that new threat actor groups, like Dark Pink, pose significant threats to corporate espionage across various industries, including technology, software, pharmaceuticals, aerospace, defense, automotive, and media/gaming.
“Dark Pink’s primary objectives revolve around stealing intellectual property, proprietary data, and trade secrets,” Bleih explained. “This emphasizes the vulnerability of these sectors to espionage activities by malicious actors.”

