Dark Pink, also known as DarkPink, dark_pink, Saaiwc Group, and Saawic, is a cyberespionage threat actor active since at least 2021, with particularly notable activity from mid-2022. It primarily targets government and military organizations, alongside educational institutions and nonprofits. Its geographic focus is Southeast Asia, with documented targeting in Vietnam, Indonesia, Brunei, Malaysia, Thailand, the Philippines, and Cambodia, as well as Bosnia and Herzegovina and Belgium. Its country of origin and state sponsorship have not been established. The group gains initial access through targeted spearphishing emails carrying malicious links or attachments. Its delivery chains include ISO images containing decoy documents, signed executables, and malicious DLLs, as well as crafted archives exploiting WinRAR vulnerability CVE-2023-38831. It has also exploited Microsoft Office vulnerability CVE-2017-0199. In October 2023, its WinRAR exploitation targeted government organizations in Vietnam and Malaysia using lures incorporating authentic government documents. These chains employed DLL side-loading, extraction and decryption of payloads embedded in decoy documents, and process injection to deploy TelePowerDropper and TelePowerBot. Dark Pink's custom malware includes TelePowerBot and KamiKakaBot, supporting remote command execution and sensitive-data collection and exfiltration. The group uses Telegram for command and control, GitHub for payload hosting, and HTTP-based services for exfiltration. Persistence mechanisms include Microsoft Excel add-ins. Additional observed behaviors include User Account Control bypass and system-information collection. The group updates its malware and uses encrypted payloads, legitimate services, and low-volume, selectively targeted campaigns to reduce detection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploits vulnerable WinRAR installations using government-document PDF lures and malicious archives to deploy TelePowerDropper and TelePowerBot through DLL side-loading.
Observed using RAR archive files as part of its activity (no further details provided in the content).
Mentioned only as a comparison for similar graphical/UI-related malware capabilities such as screenshots or screen recording.
Targets government organizations with authentic-looking government-document lures and a DLL side-loading chain that deploys TelePowerDropper and TelePowerBot.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.