Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
152 Chrome Extensions Maliciously Hide Ad Tracking
June 14, 2026
Maine AG Takes Data Breach Portal Offline After Fake
June 14, 2026
Agentjacking Attack Hijacks AI Coding Agent for Mal
June 13, 2026
Home/Threats/Pink Hacking Group Steals Enterprise Cloud Pass Attacking Users
Threats

Pink Hacking Group Steals Enterprise Cloud Pass Attacking Users

According to researchers, the Pink hacking group is affiliated with the broader Com network, a loose community of cybercriminals known for aggressive social engineering campaigns. The group also...

David kimber
David kimber
June 8, 2026 3 Min Read
17 0

According to researchers, the Pink hacking group is affiliated with the broader Com network, a loose community of cybercriminals known for aggressive social engineering campaigns.

The group also shares tactical similarities with other well-known threat actors such as Lapsus$, Scattered Spider, and ShinyHunters, suggesting a shared playbook among these communities.

Once Pink gains access to an employee’s account, the attackers move fast. They use Microsoft’s own built-in automation tools to sweep through cloud storage environments, draining files from OneDrive and SharePoint folders within minutes.

Pink Group Incidents (Source - Linkedin)
Pink Group Incidents (Source – Linkedin)

With the stolen data in hand, the group turns to compromised accounts to send internal Microsoft Teams messages and emails demanding payment, giving executives a tight 72-hour window to respond.

This internal messaging tactic makes the extortion feel more urgent and legitimate to victims.

The group also shows signs of being a possible rebrand of an older operation. Google Threat Intelligence Group analysts have assessed that after the BlackFile brand retired in May 2026, the group may have briefly operated as Redact before surfacing again as Pink.

This pattern of rebranding is common among sophisticated extortion crews seeking to evade tracking.

New Pink Hacking Group Attacking Enterprise Users

Pink’s effectiveness lies in how it avoids triggering standard security tools. Since the group uses legitimate employee accounts and Microsoft’s own internal tools to move data, most firewalls and endpoint detection systems simply do not flag the activity as suspicious.

The attackers direct victims to phishing domains such as passkeydeploy.com and deploypasskey.com, where session cookies are captured, allowing the group to bypass MFA entirely without needing the victim’s password again.

Pink Group Introduction (Source - Linkedin)
Pink Group Introduction (Source – Linkedin)

In addition to credential theft, Pink also uses fileless techniques to stay hidden within compromised environments. Rather than dropping large files onto a hard drive, the group runs small code commands that build their payload directly in the computer’s temporary memory.

This means standard antivirus programs that scan folders and drives will not detect any threat. The code also performs environment checks, and if it detects a security research sandbox, it quietly suppresses its own behavior to avoid analysis.

Protecting Your Organization From Vishing Attacks

Security experts urge organizations to take a practical, people-first approach to defending against groups like Pink.

Employees should be trained to independently verify any unexpected IT phone call before following instructions, especially when asked to visit a link or enter credentials.

Help desk teams should have strict identity verification procedures in place that cannot be bypassed through social pressure alone.

On the technical side, organizations are advised to migrate from standard one-time password MFA to phishing-resistant authentication methods such as FIDO2 hardware keys.

Security teams should monitor cloud environments for unusual spikes in file downloads, review OAuth token grants and API permissions, and block known phishing domains linked to Pink’s infrastructure.

Deploying behavioral monitoring tools that flag large, sudden data transfers before they leave the network can also make a critical difference.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain passkeyadd.com Phishing domain used to harvest enterprise credentials and MFA codes 
Domain passkeydeploy.com Phishing domain used for session cookie theft and credential harvesting 
Domain deploypasskey.com Phishing domain associated with Pink’s credential phishing infrastructure 
IP Address 185.178.208.153 Infrastructure IP linked to Pink’s phishing hosting, frequently tied to DDoS-Guard 
IP Address 172.93.100.252 Infrastructure IP associated with Pink’s phishing campaign operations 
IP Address 96.232.20.66 Infrastructure IP observed in Pink’s attack infrastructure reuse across victims 

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackphishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Lucid Stealer Targets Browsers, Crypto Wallets Discord

Next Post

Malspam Uses Google DoubleClick for Fileless . Attack Redirects

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Government Directive Blocks Anthropic Fable 5 & Mythos Access
June 13, 2026
Fancy Bear Abuses EdgeRouters & Cloud for Stealthy
June 12, 2026
Hackers Abuse NinjaOne RMM to Bypass Malware Legitimate Software
June 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us