New Pink Hacking Group Steals Cloud Storage Passwords From Enterprises
Key Takeaways The Pink hacking group, linked to the Com cybercriminal network, is actively targeting enterprises to steal cloud storage credentials and exfiltrate data. Pink employs sophisticated...
Key Takeaways
- The Pink hacking group, linked to the Com cybercriminal network, is actively targeting enterprises to steal cloud storage credentials and exfiltrate data.
- Pink employs sophisticated social engineering, including vishing, to gain initial access, then leverages legitimate Microsoft tools (OneDrive, SharePoint, Teams) for data theft and extortion.
- The group utilizes phishing domains to harvest session cookies, bypassing multi-factor authentication (MFA), and deploys fileless malware to evade traditional endpoint detection.
- Organizations are urged to enhance employee training on vishing, implement phishing-resistant MFA, and monitor cloud environments for suspicious data exfiltration.
New Pink Hacking Group Attacking Enterprise Users
A new cybercriminal entity, dubbed the “Pink” hacking group, is actively compromising enterprise cloud environments to steal sensitive data and conduct extortion. Researchers indicate that Pink operates as part of the broader Com network, a collective of cybercriminals known for their aggressive social engineering tactics. The group’s operational methods bear striking similarities to those of other prominent threat actors such as Lapsus$, Scattered Spider, and ShinyHunters, suggesting a shared tactical blueprint within these communities.
Table Of Content
Once Pink successfully compromises an employee account, their operations escalate rapidly. They exploit Microsoft’s native automation functionalities to swiftly exfiltrate files from cloud storage platforms like OneDrive and SharePoint, often completing data siphoning within minutes.
Following data theft, the group weaponizes compromised internal accounts to dispatch extortion demands via Microsoft Teams messages and emails. These communications often impose a stringent 72-hour deadline for executives to comply, leveraging the internal communication channels to amplify the perceived urgency and legitimacy of their threats.
Analysts from Google Threat Intelligence Group have observed a potential rebranding pattern, suggesting Pink may be a successor to earlier operations. After the BlackFile brand ceased operations in May 2026, the group may have briefly functioned under the moniker Redact before re-emerging as Pink. This strategic rebranding is a common tactic among advanced extortion groups aiming to obscure their tracks and evade persistent attribution, as detailed by The Register.
Advanced Evasion Techniques
Pink’s efficacy largely stems from its ability to circumvent conventional security defenses. By operating through legitimate employee accounts and utilizing Microsoft’s own internal tools for data movement, their activities often bypass standard firewalls and endpoint detection systems, which fail to flag the actions as malicious.
The attackers direct victims to deceptive phishing domains, including passkeydeploy.com and deploypasskey.com. On these sites, session cookies are harvested, enabling the group to completely bypass multi-factor authentication (MFA) without requiring the victim to re-enter their password.
Beyond credential theft, Pink employs fileless malware techniques to maintain stealth within compromised networks. Instead of dropping detectable files onto disk drives, the group executes small code commands that construct their payload directly within the computer’s volatile memory. This approach renders traditional antivirus programs, which primarily scan file systems, ineffective. Furthermore, the malicious code incorporates environment checks, designed to detect security research sandboxes and suppress its behavior, thereby hindering analysis, a technique highlighted by Hackread.
What You Should Do
Organizations must adopt a comprehensive, human-centric strategy to defend against sophisticated groups like Pink. Practical mitigation steps include:
- Enhanced Employee Training: Educate employees to independently verify the legitimacy of any unexpected IT-related phone calls, particularly when prompted to click links or enter credentials.
- Robust Help Desk Protocols: Implement stringent identity verification procedures for help desk teams that cannot be circumvented by social engineering pressure.
- Phishing-Resistant MFA: Transition from standard one-time password MFA solutions to more resilient authentication methods, such as FIDO2 hardware security keys.
- Cloud Environment Monitoring: Continuously monitor cloud environments for anomalous spikes in file downloads and review OAuth token grants and API permissions for suspicious activity.
- Domain Blocking: Proactively block known phishing domains associated with Pink’s infrastructure.
- Behavioral Monitoring: Deploy behavioral monitoring tools capable of flagging large, sudden data transfers before they exit the network perimeter.
Indicators of Compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.