← Back to all threat actors

Pink

Tracked as CL-CRI-1147

Pink is a financially motivated data-extortion cluster that uses fake internal IT calls and tailored Microsoft Entra ID or Okta phishing sites to steal authentication material. Observed activity includes theft from SharePoint and OneDrive followed by extortion through compromised corporate communications, without evidence of file encryption.

How we source and review actor profiles
Motivation
cybercrime
Last seen
2026-08-17
Sectors
healthcare-biotech, technology-saas, financial-services, professional-services, media-entertainment, construction-infrastructure-real-estate, aviation-logistics-transportation, consumer-retail-energy-food
Status
Active

Threat intelligence assessment

At a glance

Credential-driven extortion operation using voice phishing, tailored identity-provider lures, cloud-data theft, and pressure through compromised business communications.

Actor class
Data-extortion group
Motivation
Financial

Activity timeline

First observed
Early March 2026
Status
Active as of the reviewed date
Status as of
2026-08-17
Leak site live
2026-05-31

Attribution assessment

Facts

  • Likely connected to the broader Com cybercriminal ecosystem based on tradecraft similarities.
  • A likely rebrand relationship with Redact is tracked separately as an assessed relationship, not as an alias.
  • Pink's data-leak site claims that the group has no association with prior groups.

Operational playbook

Extortion deadline hours
72

Stages

  • Call employees while impersonating internal IT support.
  • Direct selected employees to a target-specific Entra ID or Okta phishing site.
  • Capture credentials and authentication responses through an operator-controlled kit.
  • Collect and exfiltrate cloud data from SharePoint and OneDrive.
  • Send extortion demands through compromised email or internal Teams messages.
  • Provide qTox and a Pink data-leak site as contact and pressure channels.

Initial access and identity targets

Methods

  • Voice phishing
  • Tailored spearphishing links
  • Internal IT impersonation

Identity Platforms

  • Microsoft Entra ID
  • Okta

Authentication Targets

  • Passwords
  • MFA number matching
  • Passkey recovery or registration workflows

Capabilities and evasion

Phishing Kits

  • Microsoft Entra ID live-panel kit
  • Operator-controlled Okta impersonation kit

Evasion

  • WebGL checks for virtualized graphics renderers
  • Headless-browser and automation artifact checks
  • Screen-size and timezone anomaly checks
  • ASN filtering for cloud, data-center, VPN, and proxy traffic
  • Human-interaction gates and hidden honeypot fields
  • Backend approval before a lure is revealed

Operator Control

  • Heartbeat telemetry and session tracking
  • Dynamic single-page application routing
  • Target-specific tenant branding
  • Live redirection between authentication stages
  • Credential exfiltration with sendBeacon and XMLHttpRequest fallback

Infrastructure patterns

Hosting Providers

  • Cloudflare
  • DDoS-Guard

Registrars

  • Tucows
  • Nicenic

Domain Patterns

  • {target_brand}.{keyword}passkey.com
  • {target_brand}.passkey{keyword}.com

Validation

  • Target-brand subdomains
  • Phishing-kit content observed in URLScan DOM captures

Communication and pressure channels

Channels

  • Compromised corporate email
  • Microsoft Teams
  • qTox
  • Pink data-leak site

Observed targeting

Targeting, not victimization. Observed brand lures indicate targeting intent and are not confirmation that an organization was compromised.
Healthcare and biotech20 · 26.7%
Technology and SaaS16 · 21.3%
Financial services16 · 21.3%
Professional services7 · 9.3%
Media and entertainment6 · 8%
Construction, infrastructure, and real estate5 · 6.7%
Aviation, logistics, and transportation3 · 4%
Consumer retail, energy, and food2 · 2.7%

Defender guidance

Measures

  • Train employees to verify unexpected internal IT calls through a separate trusted channel.
  • Prefer hardware-backed FIDO2 or WebAuthn over push-based MFA.
  • Monitor for anomalous sign-ins and unexpected authentication-method or passkey registrations.
  • Investigate target-branded subdomains on passkey-themed domains, while treating naming alone as a lead rather than attribution.

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
Indicator1 indicator cataloged

Types: domain.

Cataloged
Indicator1 indicator cataloged

Types: domain.

Cataloged
Indicator34 indicators cataloged

Types: domain.

Cataloged
RelationshipRebrand of relationship with Redact

Pink is assessed as a likely rebrand of Redact. The assessment is shown as a relationship because it is not an exact-name equivalence.

Medium
Cataloged
IdentityTracking identifier: CL-CRI-1147

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

PinkCanonical Name
CL-CRI-1147Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...