The Manila Times

Dark Pink: An advanced persistent threat campaign

-

GLOBAL cybersecur­ity company GroupIB has recently published its findings into “Dark Pink,” an ongoing advanced persistent threat (APT) campaign launched against high-profile targets in Cambodia, Indonesia, Malaysia, the Philippine­s, Vietnam, and Bosnia and Herzegovin­a that they believe, with moderate confidence, was launched by a new threat actor.

To date, Group-IB’s Threat Intelligen­ce has been able to attribute seven successful attacks to this particular group from June to December 2022, with targets including military bodies, government ministries and agencies, and religious and nonprofit organizati­ons, although the list of victims could be significan­tly longer.

Group-IB also noted one unsuccessf­ul attack on a European state developmen­t body based in Vietnam.

Group-IB analysis discovered that the initial access vector for the campaign of Dark Pink (name given by Group-IB) was targeted spear-phishing emails, and the core goal of the threat actors, who leverage an almost-entirely custom toolkit, is corporate espionage, as they attempt to exfiltrate files, microphone audio, and messenger data from infected devices and networks.

Group-IB, in line with its zero-tolerance policy to cybercrime, has issued proactive notificati­ons to all potential and confirmed targets of Dark Pink. Its researcher­s are continuing to uncover and analyze all the details behind this particular APT campaign.

Dark Pink goes to the core

To date, Group-IB has been unable to attribute this campaign, which leverages custom tools and some rarely-seen tactics and techniques, to any known threat actor. As a result, Group-IB believes that Dark Pink’s campaign in the second half of 2022 is the activity of an entirely new threat actor group, which has also been termed Saaiwc Group by Chinese cybersecur­ity researcher­s.

This new APT group is notable due to its specific focus on attacking branches of the military, and government ministries and agencies. Group-IB discovered that, as of December 2022, Dark Pink APT breached the security defenses of six organizati­ons in five APAC countries (Cambodia, Indonesia, Malaysia, the Philippine­s and Vietnam), and one organizati­on in Europe (Bosnia and Herzegovin­a). The first successful attack took place this past june, when the threat actors gained access to the network of a religious organizati­on in Vietnam.

Following this particular breach, no other attack attributab­le to Dark Pink was registered until August 2022, when Group-IB analysts discovered that the threat actors had gained access to the network of a Vietnamese non-profit organizati­on.

“Group-IB’s analysis of Dark Pink is of major significan­ce, as it details a highly complex APT campaign launched by seasoned threat actors. The use of an almost entirely custom toolkit, advanced evasion techniques, the threat actors’ ability to rework their malware to ensure maximum effectiven­ess, and the profile of the targeted organizati­ons demonstrat­e the threat that this particular group poses. Group-IB will continue to monitor and analyze both past and future Dark Pink attacks with the aim of uncovering those behind this campaign,” said Andrey Polovinkin, malware analyst at Group-IB.

Dark Pink APT’s recent campaign is yet another example of how individual­s’ interactio­ns with spear-phishing emails could result in the penetratio­n of the security defenses of even the most protected organizati­ons. GroupIB recommends solutions, such as its proprietar­y Business Email Protection, that could counter this threat effectivel­y and stop malicious emails from ending up in employees’ inboxes.

That said, Group-IB urges organizati­ons to foster a culture of cybersecur­ity and educate their employees on how to identify phishing emails. Group-IB’s Threat Intelligen­ce platform led the analysis into Dark Pink, which could help organizati­ons shore up their security posture by equipping them with the latest insights into emerging threats.

Newspapers in English

Newspapers from Philippines