Pink, also identified as CL-CRI-1147, is a financially motivated cybercriminal extortion brand active in 2026 that targets enterprise cloud accounts through voice phishing and identity-based social engineering. Its campaigns have targeted organizations in technology, healthcare, food and beverage, automotive, construction, aviation, and financial services. Operators impersonate internal IT support personnel and claim that employees must enroll passkeys or update authentication settings. They direct victims to organization-branded phishing portals that imitate Microsoft Entra ID or other enterprise identity services. Pink uses operator-controlled phishing kits to capture credentials and satisfy multifactor authentication challenges in real time. The kits accommodate SMS codes, time-based one-time passwords, and push notifications with number matching. Staged passkey-enrollment and recovery screens keep victims occupied while operators obtain authenticated access. Following compromise, Pink identifies and exfiltrates sensitive data from SharePoint and OneDrive, then uses compromised accounts to deliver extortion demands through email and internal Microsoft Teams messages. Its operations focus on stolen-data extortion rather than file encryption. Pink shares phishing templates and infrastructure with activity associated with the UNC6671 cluster and the BlackFile, Redact, Helix, and Falcon extortion brands. These infrastructure links do not establish that all of the brands are aliases of a single organization. Pink's tradecraft centers on cloud identity compromise, rapid data theft, and monetization of sensitive organizational information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Com-associated brand characterized by passkey-themed phishing domains and infrastructure patterns similar to FALCON.
An extortion group Google linked to UNC6671 activity and the same broader extortion ecosystem.
Data-extortion operations potentially continued or rebranded as Cinder.
One of four brands used in BlackFile's split extortion operations sharing infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.