Pink is a data extortion threat actor tracked by Palo Alto Networks Unit 42 as CL-CRI-1147. The group emerged in 2026 and is associated with a social-engineering-led intrusion model focused on compromising enterprise identity and cloud collaboration environments rather than deploying traditional ransomware. Reporting has linked Pink to the broader Com cybercriminal ecosystem, and some researchers assess it may represent a rebrand or successor operation connected to Redact and BlackFile, though such lineage remains an assessment rather than confirmed attribution. Pink primarily targets enterprise organizations, with observed victimology concentrated in the United States across healthcare, biotechnology, technology, SaaS, and financial services, while additional activity has also affected sectors including food and beverage, automotive, construction, and aviation. The actor appears to favor organizations where access to Microsoft 365 or Okta-backed identity workflows can quickly yield sensitive business data stored in SharePoint, OneDrive, and related cloud services. Its initial access tradecraft relies heavily on voice phishing and impersonation of internal IT or help-desk personnel. Operators contact employees by phone, direct them to phishing pages themed around Microsoft Entra ID or Okta, and harvest credentials, MFA responses, and in some cases session material sufficient to bypass normal authentication controls. A notable lure involves fake Microsoft Entra passkey enrollment, in which victims are guided through staged enrollment and recovery workflows while the attackers authenticate to the real tenant and establish persistence. Researchers have also described phishing kits capable of adapting to different MFA methods, including TOTP, SMS one-time codes, and push-based number matching. Pink’s phishing infrastructure and kits show a comparatively mature level of operational security and anti-analysis behavior. Observed kits use dynamic branding to mimic the victim organization, backend-controlled gating, heartbeat polling, anti-bot checks, browser and environment fingerprinting, and logic intended to block cloud-hosted analysis systems, virtual machines, headless browsers, and other researcher environments. Some reporting also describes fileless or memory-resident execution techniques and evasive behavior designed to reduce endpoint visibility. After account compromise, Pink rapidly identifies and exfiltrates data from SharePoint and OneDrive, often using legitimate Microsoft tooling and built-in automation rather than conspicuous malware. The group then leverages compromised internal accounts to send extortion messages by email and Microsoft Teams, typically imposing short response deadlines and threatening publication of stolen data via a dedicated leak site. This reflects a pure data-theft-and-extortion model rather than encryption-based ransomware operations. Pink’s tactics, techniques, and procedures overlap with social-engineering-centric extortion actors such as Scattered Spider, ShinyHunters, and Lapsus$, particularly in the use of vishing, fake help-desk pretexts, cloud identity compromise, and abuse of legitimate enterprise platforms for collection and extortion. Multiple assessments characterize Pink as likely Com-affiliated, and some reporting suggests it may be part of the post-BlackFile fragmentation that also produced Redact. High-confidence characterization supports Pink as a cloud-focused, identity-driven extortion brand specializing in rapid credential theft, MFA bypass, SaaS data exfiltration, and coercive follow-on extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in passing as another group that may be linked to BlackFile.
Named as one of the brands that emerged after BlackFile’s collapse, providing ecosystem context around Helix.
Conducting vishing-assisted phishing and data extortion campaigns by impersonating IT staff, stealing Microsoft 365 credentials and MFA factors through fake Entra passkey enrollment flows, enrolling attacker-controlled passkeys, exfiltrating data from SharePoint and OneDrive, and sending extortion messages from compromised accounts.
Mentioned as a potential successor in the same data-extortion ecosystem discussed around Helix and BlackFile.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.