Security researchers reported two active phishing operations that relied on social engineering rather than mass malware spam to compromise organizations and steal high-value data. Proofpoint said the cluster it tracks as UNK_DeadDrop, likely aligned with North Korea, targeted developers at nearly 100 organizations in cryptocurrency, finance, technology, and education. The attackers used fake recruitment, code review, and technical assessment lures to push victims to attacker-controlled GitHub and GitLab repositories, where hidden Visual Studio Code tasks and a malicious VSIX extension triggered malware on macOS, Linux, and Windows. The campaign stole browser credentials, cryptocurrency wallets, cookies, and keychain or keyring data, while maintaining persistence through the extension and removing repository artifacts to reduce detection.
A separate campaign tracked by Palo Alto Networks Unit 42 as CL-CRI-1147 and publicly associated with the Pink extortion group targeted enterprise users through voice phishing and credential theft. Researchers said Pink impersonated internal IT staff to direct employees to phishing pages that captured credentials, MFA codes, and session cookies, enabling access to Microsoft 365 services including OneDrive and SharePoint. The group then used legitimate Microsoft automation tools to exfiltrate data and sent extortion demands through compromised Microsoft Teams accounts and email, typically giving victims 72 hours to pay. Unit 42 linked Pink to the broader Com cybercriminal ecosystem and noted overlaps with groups such as Lapsus$, Scattered Spider, and ShinyHunters, while Google Threat Intelligence Group assessed it may be a rebrand of the BlackFile operation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-09, Gurucul published detection content for the UNK_DeadDrop phishing campaign, including a query to identify email activity involving a defined set of suspicious addresses. The published indicators spanned multiple domains and HR-themed aliases, providing additional infrastructure details for threat hunting.
Palo Alto Networks Unit 42 identified Pink as a newly tracked extortion group, CL-CRI-1147, and linked it to the broader Com cybercriminal community. Researchers noted similarities to Lapsus$, Scattered Spider, and ShinyHunters, and described Pink's use of vishing, credential theft, cloud data exfiltration, and extortion via compromised Microsoft 365 accounts.
Google Threat Intelligence Group assessed that Pink may be a rebrand of the BlackFile operation and said BlackFile retired in May 2026. The report also suggested there may have been a brief Redact phase between BlackFile and Pink.
Between April and May 2026, a phishing campaign tracked by Proofpoint as UNK_DeadDrop targeted developers at nearly 100 organizations, particularly in cryptocurrency, finance, technology, and education. The activity used recruitment, code review, and technical testing lures to direct victims to attacker-controlled GitHub and GitLab repositories.
Proofpoint disclosed a likely North Korea-aligned campaign cluster named UNK_DeadDrop on 2026-06-05. The company said the operation abused Visual Studio Code and Cursor workflows, hidden VS Code tasks, and a malicious VSIX extension to deliver malware across macOS, Linux, and Windows.
The extortion group Pink launched a dedicated data leak site on 2026-05-31. The group uses voice phishing and credential theft to compromise enterprise users and extort victims after data exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcerhisac.org
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourceproofpoint.com
Open sourcearcticwolf.com
Open sourceany.run
Open sourceabout.gitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.