TelePowerBot is a custom Windows remote access Trojan used by the Dark Pink cyberespionage group to remotely control compromised hosts and exfiltrate sensitive data. It is part of the group's malware arsenal alongside KamiKakaBot. Dark Pink primarily targets government and military organizations, with additional targeting of educational institutions and nonprofits, particularly in Southeast Asia. TelePowerBot can maintain persistence through a Microsoft Excel add-in.
TelePowerBot is installed by TelePowerDropper. Documented deployment campaigns exploited CVE-2023-38831 in WinRAR against government organizations in Vietnam and Malaysia in October 2023, using archives with government-document PDF lures. The infection chain launches an executable that side-loads a malicious DLL, extracts encrypted payload data from the decoy PDF, and decrypts and injects a portable executable into the parent process. This loads TelePowerDropper, which installs TelePowerBot. Dark Pink also uses spear-phishing with malicious links and attachments, including ISO files containing decoy documents, signed executables, and malicious DLLs. Its operations use Telegram for command and control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-38831 is a vulnerability that enables malicious actors to execute arbitrary code when a user tries to access a harmless file contained within a ZIP archive.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dark Pink employs a set of custom malware tools, notably TelePowerBot and KamiKakaBot. These tools are designed to exfiltrate sensitive data from compromised hosts.
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-control trojan installed by TelePowerDropper in DarkPink campaigns exploiting WinRAR against government organizations in Vietnam and Malaysia.
Remote-control trojan installed by TelePowerDropper in DarkPink's WinRAR exploitation campaign targeting government organizations in Vietnam and Malaysia.
Custom malware used by Dark Pink to exfiltrate sensitive information from compromised hosts. The group uses a Microsoft Excel add-in to maintain TelePowerBot persistence. The article reports updates to the malware intended to impede analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.