Pink is a financially motivated data-extortion brand active in 2026 and tracked by some vendors as CL-CRI-1147. It is associated with social-engineering-led intrusions that target enterprise cloud identities and collaboration platforms rather than malware deployment or encryption-based ransomware. Multiple assessments link Pink to the broader UNC6671/BlackFile ecosystem, with Pink described as one of several successor or parallel extortion brands alongside Redact, Helix, and Falcon after the BlackFile brand was retired. Pink has also been assessed as likely affiliated with The Com, a loosely connected English-speaking cybercriminal milieu associated with aggressive identity-focused extortion operations. Pink’s core intrusion method is voice phishing. Operators impersonate internal IT or help-desk personnel, often creating urgency around security migrations, passkey enrollment, MFA changes, or account issues, and direct employees to spoofed Microsoft Entra ID or Okta login portals. The phishing infrastructure is tailored to the victim organization and is designed to capture credentials, MFA factors, and in some cases session material. Reported tradecraft includes adversary-in-the-middle credential harvesting, passkey-themed lures, fake recovery-key workflows, and phishing kits that adapt to different MFA methods including push-based approval, number matching, SMS codes, and TOTP. Pink’s kits have also been described as using anti-analysis and researcher-blocking features, dynamic branding, backend-controlled gating, and other evasion measures. After initial access, Pink rapidly abuses compromised Microsoft 365 identities to access SharePoint and OneDrive, steal sensitive corporate data, and maintain access. Reported post-compromise behavior includes use of legitimate cloud and automation tooling, session abuse, and persistence through attacker-controlled passkey or MFA enrollment. Pink then monetizes access through data-theft extortion, typically threatening to publish stolen information on a leak site unless payment is made. Extortion communications have been sent through compromised email accounts and internal collaboration platforms such as Microsoft Teams, often with short response deadlines. Pink is therefore best characterized as an identity-centric extortion actor focused on fast cloud data theft and coercive monetization rather than disruptive encryption. Observed targeting has included enterprises in healthcare, technology, financial services, food and beverage, automotive, construction, aviation, private equity, and professional services. Broader UNC6671-linked reporting also places related activity against legal organizations and other high-value firms holding confidential corporate, transactional, and client data. Pink’s victimology and tradecraft indicate a preference for organizations where stolen cloud data can create strong financial leverage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
One of four successor brands/groups that UNC6671/BlackFile reportedly split into, continuing the same vishing and extortion tradecraft.
Extortion brand associated with UNC6671; described as conducting Big Game Hunting with tailored Okta and Microsoft Entra ID phishing kits and gated phishing infrastructure.
A named extortion-focused cluster targeting large U.S. financial and investment firms using vishing to steal credentials and MFA codes via spoofed websites, then threatening to leak stolen data.
Mentioned only in passing as another group that may be linked to BlackFile.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.