Pink is a financially motivated data-extortion brand active in 2026 and commonly tracked as CL-CRI-1147. It is associated by multiple security vendors with the broader UNC6671 / BlackFile ecosystem and is widely assessed as likely Com-affiliated. Reporting consistently links Pink with the related extortion brands Redact, Helix, and Falcon through shared infrastructure, overlapping victimology, and near-identical phishing tradecraft. Some assessments describe Pink as a successor or rebrand that emerged after the BlackFile brand was retired, although the exact organizational relationship among these brands remains unresolved. Pink specializes in identity-centric intrusions against enterprise cloud environments rather than malware-led network compromise. Its primary initial-access method is voice phishing in which operators impersonate internal IT or help-desk personnel, often creating urgency around security migrations, MFA enrollment, or passkey setup. Victims are directed to spoofed Microsoft Entra ID or Okta login portals designed to capture credentials, MFA factors, and in some cases authenticated sessions. Observed phishing workflows include tailored branding for the victim organization, adaptive MFA handling, and passkey-themed lures intended to distract the user while the actor enrolls attacker-controlled authentication methods. Post-compromise activity centers on rapid access to SaaS and identity platforms, especially Microsoft 365, SharePoint, OneDrive, and in some reporting Okta. Pink has been observed stealing credentials and session material, establishing persistence through account and authentication abuse, and quickly identifying and exfiltrating sensitive corporate data from cloud repositories. Extortion is then conducted using compromised internal accounts, including email and collaboration platforms, with threats to leak stolen data via a dedicated leak site. Pink is characterized as an extortion actor focused on data theft rather than encryption-based ransomware deployment. Victim targeting has included enterprise organizations across health care, technology, financial services, transportation, hospitality, manufacturing, real estate, insurance, food and beverage, automotive, construction, aviation, and legal or private-equity-related environments. Reporting indicates a concentration on U.S.-based organizations and on victims likely to hold high-value corporate, customer, or transaction-sensitive information. Pink’s tradecraft overlaps with social-engineering-heavy extortion actors linked to The Com, including activity patterns reminiscent of BlackFile, Scattered Spider, and ShinyHunters.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
One of four brands used in BlackFile's split extortion operations sharing infrastructure.
Named extortion brand sharing infrastructure with UNC6671-linked operations.
Extortion brand sharing infrastructure with Helix within the broader UNC6671-linked activity cluster.
One of four successor brands/groups that UNC6671/BlackFile reportedly split into, continuing the same vishing and extortion tradecraft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.