DarkPink (Saaiwc) is an APT group targeting government and military entities in Southeast Asia and Europe.
Analyst brief
DarkPink (Saaiwc) is an APT group active since mid-2021. It primarily targets government, military, and non-profit organizations in Southeast Asia and Europe. Their key TTPs include spear phishing with ISO images and malicious PDFs to deliver custom Trojans like TelePowerBot and KamiKakaBot, exploiting CVE-2023-38831, and maintaining persistence via DLL side-loading and scheduled tasks. Defenders should focus on email security, unusual file formats, and scheduled task anomalies.
DarkPink
Saaiwc
unknown
DarkPink is an APT group that has been active since mid-2021, primarily targeting government, military, and non-profit organizations in Southeast Asia and Europe. The group employs spear phishing techniques, utilizing ISO images and malicious PDF files to deliver custom Trojan programs like TelePowerBot and KamiKakaBot for information theft. They have exploited vulnerabilities such as CVE-2023-38831 to enhance their attack processes and maintain persistence through DLL side-loading and scheduled tasks. DarkPink's operations are characterized by stealth and precision, making them a significant threat in the cyber landscape.