DIRECTORY

  • Alerts
  • APTs
  • Blog
  • Books
  • Certifications
  • Cheat Sheets
  • Courses
  • Cyber Briefing
  • CyberDecoded
  • CyberReview
  • CyberStory
  • CyberTips
  • Definitions
  • Domains
  • Entertainment
  • FAQ
  • Frameworks
  • Hardware Tools
  • Incidents
  • Malware
  • News
  • Papers
  • Podcasts
  • Quotes
  • Reports
  • Tools
  • Threats
  • Tutorials
No Result
View All Result
  • Login
  • Register
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
Get Help
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
No Result
View All Result
Get Help
CyberMaterial
Home Alerts

Dark Pink APT Targets Southeast Asia

March 13, 2023
Reading Time: 2 mins read
in Alerts

 

The Dark Pink advanced persistent threat (APT) group, also known as Saaiwc, has been linked to a new wave of attacks on government and military entities in Southeast Asia.

The attacks used a malware called KamiKakaBot, which is designed to steal data stored in web browsers and execute remote code using Command Prompt, while also evading detection. Dark Pink is believed to be of Asia-Pacific origin and has been active since mid-2021, with an increased tempo observed in 2022.

The latest attacks, which took place in February 2023, were almost identical to previous attacks, according to Dutch cybersecurity company EclecticIQ.

The attacks played out as social engineering lures containing ISO image file attachments in email messages to deliver the malware. The ISO image includes an executable, a loader, and a decoy Microsoft Word document, the latter of which comes embedded with the KamiKakaBot payload.

Persistence on the compromised host is achieved by making malicious Windows Registry key modifications using the Winlogon Helper library. The gathered data is then exfiltrated to a Telegram bot as a ZIP archive.

The use of legitimate web services such as Telegram as a command-and-control (C2) server is the number one choice for different threat actors, from regular cybercriminals to advanced persistent threat actors, according to EclecticIQ.

The Dark Pink APT group is likely a cyber espionage-motivated threat actor that exploits relations between ASEAN and European nations to create phishing lures.

Organizations in Southeast Asia should remain vigilant against social engineering lures containing ISO image file attachments in email messages, and they should use anti-malware measures and leverage third-party threat intelligence to detect and respond to attacks.

They should also use multi-factor authentication, segmentation, and network-based security controls to prevent the spread of malware and reduce the attack surface.

Additionally, organizations should establish a robust incident response plan and practice incident response exercises to minimize the impact of attacks.

Read More

Tags: Advanced Persistent ThreatAlertsAlerts 2023Dark PinkGovernmentInstitutionsKamiKakaBotMalwareMarch 2023MilitaryPhishingSaaiwcSoutheast Asia
2
VIEWS
ADVERTISEMENT

Related Posts

TOR installers target crypto users

TOR installers target crypto users

March 29, 2023
ABB Security Advisory: RCCMD Vulnerability

ABB Security Advisory: RCCMD Vulnerability

March 29, 2023
Flaw in WiFi protocol allows plaintext leak

Flaw in WiFi protocol allows plaintext leak

March 29, 2023
Europol warns about AI abuse

Europol warns about AI abuse

March 29, 2023

More Articles

Entertainment

Cyber Motherboard Podcast

February 3, 2021
Alerts

[Control Systems] Schneider Electric Security Advisory

December 14, 2021

Cloudy with a chance of Trust

February 10, 2022
Cyber101

Business Continuity Planning (BCP)

June 14, 2022

Security through data

Cybersecurity Domains

  • API Security
  • Business Continuity
  • Career Development
  • Compliance
  • Cryptography
  • HSM
  • KPIs / KRIs
  • Penetration Testing
  • Shift Left
  • Vulnerability Scan

Emerging Technologies

  • 5G
  • Artificial Intelligence
  • Blockchain
  • Cryptocurrency
  • Deepfake
  • E-Commerce
  • Healthcare
  • IoT
  • Quantum Computing

Frameworks

  • CIS Controls
  • CCPA
  • GDPR
  • NIST
  • 23 NYCRR 500
  • HIPAA

Repository

  • Books
  • Certifications
  • Definitions
  • Documents
  • Entertainment
  • Quotes
  • Reports

Threats

  • APTs
  • DDoS
  • Insider Threat
  • Malware
  • Phishing
  • Ransomware
  • Social Engineering

© 2023 | CyberMaterial | All rights reserved.

World’s #1 Cybersecurity Repository

  • About
  • Legal and Privacy Policy
  • Site Map
No Result
View All Result
  • Audience
    • Cyber Citizens
    • Cyber Professionals
    • Institutions
  • Highlights
    • Blog
    • CyberDecoded
    • Cyber Review
    • CyberStory
    • CyberTips
  • Cyber Risks
    • Alerts
    • Attackers
    • Domains
    • Incidents
    • Threats
  • Opportunities
    • Events
    • Jobs
  • Repository
    • Books
    • Certifications
    • Cheat Sheets
    • Courses
    • Definitions
    • Frameworks
    • Games
    • Hardware Tools
    • Memes
    • Movies
    • Papers
    • Podcasts
    • Quotes
    • Reports
  • Report Cyber Incident
  • GET HELP

Subscribe to our newsletter

© 2022 Cybermaterial - Security Through Data .

Welcome Back!

Sign In with Google
Sign In with Linked In
OR

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
Sign Up with Linked In
OR

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.