Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
SilverFox Hijacks Drivers to Disable Security Tools
August 7, 2026
Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks
August 6, 2026
Vanta Stealer Drains Browser, Crypto, and Gaming Accounts
August 6, 2026
Home/Threats/New Pink Hacking Group Steals Cloud Storage Passwords From Enterprises
Threats

New Pink Hacking Group Steals Cloud Storage Passwords From Enterprises

Key Takeaways The Pink hacking group, linked to the Com cybercriminal network, is actively targeting enterprises to steal cloud storage credentials and exfiltrate data. Pink employs sophisticated...

David kimber
David kimber
June 8, 2026 3 Min Read
52 0

Key Takeaways

  • The Pink hacking group, linked to the Com cybercriminal network, is actively targeting enterprises to steal cloud storage credentials and exfiltrate data.
  • Pink employs sophisticated social engineering, including vishing, to gain initial access, then leverages legitimate Microsoft tools (OneDrive, SharePoint, Teams) for data theft and extortion.
  • The group utilizes phishing domains to harvest session cookies, bypassing multi-factor authentication (MFA), and deploys fileless malware to evade traditional endpoint detection.
  • Organizations are urged to enhance employee training on vishing, implement phishing-resistant MFA, and monitor cloud environments for suspicious data exfiltration.

New Pink Hacking Group Attacking Enterprise Users

A new cybercriminal entity, dubbed the “Pink” hacking group, is actively compromising enterprise cloud environments to steal sensitive data and conduct extortion. Researchers indicate that Pink operates as part of the broader Com network, a collective of cybercriminals known for their aggressive social engineering tactics. The group’s operational methods bear striking similarities to those of other prominent threat actors such as Lapsus$, Scattered Spider, and ShinyHunters, suggesting a shared tactical blueprint within these communities.

Table Of Content

  • Key Takeaways
  • New Pink Hacking Group Attacking Enterprise Users
  • Advanced Evasion Techniques
  • What You Should Do

Once Pink successfully compromises an employee account, their operations escalate rapidly. They exploit Microsoft’s native automation functionalities to swiftly exfiltrate files from cloud storage platforms like OneDrive and SharePoint, often completing data siphoning within minutes.

Following data theft, the group weaponizes compromised internal accounts to dispatch extortion demands via Microsoft Teams messages and emails. These communications often impose a stringent 72-hour deadline for executives to comply, leveraging the internal communication channels to amplify the perceived urgency and legitimacy of their threats.

Analysts from Google Threat Intelligence Group have observed a potential rebranding pattern, suggesting Pink may be a successor to earlier operations. After the BlackFile brand ceased operations in May 2026, the group may have briefly functioned under the moniker Redact before re-emerging as Pink. This strategic rebranding is a common tactic among advanced extortion groups aiming to obscure their tracks and evade persistent attribution, as detailed by The Register.

Advanced Evasion Techniques

Pink’s efficacy largely stems from its ability to circumvent conventional security defenses. By operating through legitimate employee accounts and utilizing Microsoft’s own internal tools for data movement, their activities often bypass standard firewalls and endpoint detection systems, which fail to flag the actions as malicious.

The attackers direct victims to deceptive phishing domains, including passkeydeploy.com and deploypasskey.com. On these sites, session cookies are harvested, enabling the group to completely bypass multi-factor authentication (MFA) without requiring the victim to re-enter their password.

Beyond credential theft, Pink employs fileless malware techniques to maintain stealth within compromised networks. Instead of dropping detectable files onto disk drives, the group executes small code commands that construct their payload directly within the computer’s volatile memory. This approach renders traditional antivirus programs, which primarily scan file systems, ineffective. Furthermore, the malicious code incorporates environment checks, designed to detect security research sandboxes and suppress its behavior, thereby hindering analysis, a technique highlighted by Hackread.

What You Should Do

Organizations must adopt a comprehensive, human-centric strategy to defend against sophisticated groups like Pink. Practical mitigation steps include:

  • Enhanced Employee Training: Educate employees to independently verify the legitimacy of any unexpected IT-related phone calls, particularly when prompted to click links or enter credentials.
  • Robust Help Desk Protocols: Implement stringent identity verification procedures for help desk teams that cannot be circumvented by social engineering pressure.
  • Phishing-Resistant MFA: Transition from standard one-time password MFA solutions to more resilient authentication methods, such as FIDO2 hardware security keys.
  • Cloud Environment Monitoring: Continuously monitor cloud environments for anomalous spikes in file downloads and review OAuth token grants and API permissions for suspicious activity.
  • Domain Blocking: Proactively block known phishing domains associated with Pink’s infrastructure.
  • Behavioral Monitoring: Deploy behavioral monitoring tools capable of flagging large, sudden data transfers before they exit the network perimeter.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain passkeyadd.com Phishing domain used to harvest enterprise credentials and MFA codes
Domain passkeydeploy.com Phishing domain used for session cookie theft and credential harvesting
Domain deploypasskey.com Phishing domain associated with Pink’s credential phishing infrastructure
IP Address 185.178.208.153 Infrastructure IP linked to Pink’s phishing hosting, frequently tied to DDoS-Guard
IP Address 172.93.100.252 Infrastructure IP associated with Pink’s phishing campaign operations
IP Address 96.232.20.66 Infrastructure IP observed in Pink’s attack infrastructure reuse across victims

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackphishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Lucid Stealer Targets 18 Browsers, Crypto Wallets, Discord Tokens

Next Post

Malspam Uses Google DoubleClick Redirects to Deliver Fileless .NET Loader

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical WSUS Vulnerability Lets Attackers Compromise Enterprise Endpoints
August 6, 2026
Critical Paperclip Flaws Let Attackers Gain Admin Access
August 6, 2026
Fake Movie Download Exposes Passwords, Payments, Crypto Assets
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us