Dark Pink, also known as Saaiwc Group, is an intrusion set assessed as China-nexus and active since at least mid-2022. The group has conducted cyber-espionage operations primarily against government, military, and non-profit organizations across Southeast Asia and parts of Europe. Reported victim geography includes Brunei, Cambodia, Indonesia, Malaysia, Thailand, the Philippines, Vietnam, Bosnia and Herzegovina, and Belgium. Dark Pink is associated with spearphishing-led intrusions and use of archive-based delivery mechanisms, including RAR files. The group has also been linked to malware capabilities involving user surveillance such as screenshots or screen recording. Broader reporting places Dark Pink among China-aligned intrusion sets that support strategic intelligence collection and regional geopolitical objectives. Within that context, the group fits a pattern of targeting public-sector and defense-related entities, especially in Asia, while also reaching into European organizations of diplomatic or strategic relevance. Dark Pink has additionally been noted in connection with the revival of USB devices as an intrusion vector or propagation mechanism among China-nexus actors. Its operational profile is consistent with espionage-focused activity emphasizing initial access through social engineering, persistence within victim environments, post-compromise collection, and exfiltration of sensitive information rather than disruptive or financially motivated operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Observed using RAR archive files as part of its activity (no further details provided in the content).
Mentioned only as a comparison for similar graphical/UI-related malware capabilities such as screenshots or screen recording.
Dark Pink is an emerging China-nexus intrusion set active since mid-2022, targeting government, military, non-profit, and education sectors in Southeast Asia and Europe, primarily via spear-phishing and USB-based lateral movement.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.