Dark Pink — APT Profile
Dark Pink is an advanced persistent threat cluster first publicly documented by Group-IB in January 2023, with activity traced back to mid-2021; Chinese researchers independently track the same or an overlapping cluster as "Saaiwc Group". The group conducts spear-phishing-based espionage against government ministries, military bodies, and religious/non-profit organizations primarily in Southeast Asia (including Cambodia, Vietnam, Thailand, Indonesia, Malaysia, the Philippines and Brunei), with additional victims in Europe (Bosnia and Herzegovina, Belgium). Its custom toolkit includes the info-stealers Cucky and Ctealer and the Telegram-API-based implants TelePowerBot and its .NET successor KamiKakaBot, used for command execution and exfiltration of documents, browser data and messenger contents; reported activity declined sharply after 2022-2023 but small clusters of attacks have continued to be observed since.Also tracked as
Saaiwc Group, Saaiwc
Countries linked to this actor
- Thailand targets