Home/Threat Actor/Dark Pink
Threat Actor

Dark Pink

dark_pink · china · active since 2021

Dark Pink (Saaiwc Group / APT-Q-27 / G1014) is a cyber-espionage cluster active since at least mid-2021 and publicly disclosed by Group-IB in January 2023, predominantly assessed as China-aligned by Chinese-vendor research but with attribution still genuinely contested, responsible for sustained campaigns against Southeast Asian government, military, foreign-affairs, religious, and non-profit targets across the Philippines, Cambodia, Vietnam, Indonesia, Malaysia, Brunei, Thailand, and Myanmar, plus European-diplomatic and Pacific adjacencies, defined operationally by the signature KamiKakaBot .NET implant, the TelePowerBot Telegram-C2 variant, and a distinctive heavy abuse of GitHub, Telegram, Dropbox, and Microsoft 365 services for command-and- control.

china confidence: medium 10 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited3

Profile

Dark Pink (also tracked as Saaiwc Group, APT-Q-27, and MITRE ATT&CK G1014) is a cyber-espionage cluster active since at least mid-2021, publicly disclosed by Group-IB in January 2023 under the enduring "Dark Pink" name. The cluster is widely characterized as China- aligned by Chinese-vendor research (Anheng's Saaiwc Group tracking and QiAnXin RedDrip Team's APT-Q-27 tracking) but Group-IB, authoring the seminal public profile, has remained explicitly cautious on attribution. The underlying state-sponsorship question remains genuinely open. No formal government attribution has been issued by any state. Targeting focus is overwhelmingly directed at Southeast Asian government, military, foreign-affairs, and diplomatic entities, Philippines, Cambodia, Vietnam, Indonesia, Malaysia, Brunei, Thailand, Myanmar, plus religious organizations and non-profit entities in the same region, with a smaller European subset (Bosnia and Herzegovina Presidency, Belgian development-aid agencies) and Pacific expansion (Papua New Guinea) documented in 2024 reporting. Group-IB's initial disclosure cited seven confirmed victim organizations with probable additional victims.

subsequent reporting has expanded the victim count meaningfully. Operationally Dark Pink is recognized by a distinctive multi-stage attack chain anchored on the KamiKakaBot .NET-based Windows implant. Initial access is overwhelmingly via spear-phishing with weaponized Office documents, RTF and DOCX template-injection lures (T1221), and ISO/MSI archive attachments containing decoy documents and staged executable loaders (step1.exe / step2.exe). The KamiKakaBot implant provides modular command execution, file collection, and exfiltration capability. A distinctive cluster signature is heavy abuse of legitimate cloud-and-messaging services for command-and-control: GitHub repositories for configuration and payload staging, Telegram messaging-platform bot APIs for C2 (the TelePowerBot variant disclosed by Group-IB in May 2023), Dropbox, and Microsoft 365 services. This service- abuse tradecraft provides plausible egress, complicates network- detection, and complicates infrastructure takedown. Beyond KamiKakaBot the cluster operates Cucky and Ctealer info-stealers (browser credential and cookie collection), plus living-off-the-land tooling (mshta, rundll32, PowerShell, certutil, schtasks). The cluster does not appear to operate at the technical sophistication tier of the major PRC clusters (APT41, the Typhoon family, Mustang Panda, APT10) and does not engage in supply-chain compromise or hypervisor-level operations; its strength is operational tempo, regional collection focus, and disciplined cloud-service-abuse C2 tradecraft. A handful of operational notes: First, the underlying state attribution remains genuinely open. Chinese-vendor characterizations as China-aligned and Group-IB's explicit caution should both be treated as part of the live analytic question. The Vietnamese-language-lure usage in some campaigns has prompted alternative-attribution speculation but has not produced a consensus alternative. Second, the cluster's heavy use of GitHub as a payload-and- configuration channel is distinctive among publicly-tracked Southeast-Asia-focused clusters. Defensive monitoring of GitHub-fetch patterns by victim networks is among the more productive detection approaches. Third, the cluster is comparatively newly-disclosed (Group-IB January 2023) and the public reporting corpus is still expanding; assessments may shift meaningfully as additional victim organizations are disclosed and as cluster operational signatures are further consolidated.

Aliases

10
dark pinkdark_pinkdarkpinksaaiwc groupsaaiwc_groupsaaiwcapt-q-27apt_q_27aptq27g1014

Notable Campaigns

8
2024-2025Continued Operations (2024-2025)
2024Papua New Guinea and Pacific Expansion (2024)
2023-2024Continued KamiKakaBot / TelePowerBot Operations (2023-2024)
2023-2024European Diplomatic Adjacency (2023-2024)
2023Group-IB Dark Pink Initial Disclosure (January 2023)
2023Anheng Saaiwc Group Disclosure (China-Language, 2023)
2023Group-IB Dark Pink Follow-Up Reporting (May 2023)
2023Religious-Organization Targeting in Vietnam and ASEAN (2023)

Attribution & Reporting

Attributed by
Group-IBAnheng Threat Intelligence CenterQiAnXin RedDrip360 Threat Intelligence CenterTrend MicroMicrosoftKasperskyCyfirmaCluster25SentinelOneCybleESETRecorded Future Insikt GroupK7 ComputingVolexity
Key reporting
reportGroup-IB: Dark Pink APT Group Strikes Government Entities in South Asian Countries (January 11, 2023), seminal cluster naming
reportGroup-IB: Dark Pink, Episode 2 (May 2023)
reportAnheng Threat Intelligence Center: Saaiwc Group Analysis (Chinese-language, 2023)
reportQiAnXin RedDrip: APT-Q-27 Tracking (Chinese-language, 2023)
reportTrend Micro: Exploring the Dark Pink APT Group's Targeted Attacks in ASEAN (November 2023)
reportCyfirma: Dark Pink APT Strikes ASEAN Targets (2023)
reportCluster25: Dark Pink APT Tracking (2023-2024)
reportSentinelOne Labs: Dark Pink APT Operational Analysis (2023)
reportCyble Research and Intelligence Labs: Dark Pink APT Group Targets Asian Countries (March 2023)
reportRecorded Future Insikt Group: Dark Pink APT Tracking
reportMalpedia Actor Profile: Dark Pink
reportMITRE ATT&CK Group G1014, Dark Pink

Operational

State sponsor

Suspected China-aligned advanced persistent threat group. Attribution remains genuinely contested across the vendor research community. Chinese vendor research (Anheng Threat Intelligence Center tracking the cluster as "Saaiwc Group," and QiAnXin RedDrip Team tracking as "APT-Q-27") has characterized the cluster as China-aligned.

Group-IB, which authored the seminal January 2023 public disclosure that gave the cluster its enduring "Dark Pink" name, has remained explicitly cautious on attribution, declining to assign state sponsorship in either initial or follow-on reporting. Several analysts have proposed alternative attributions: the cluster's heavy targeting of Vietnamese government and military entities, combined with use of Vietnamese-language lure documents in some campaigns, has prompted speculation that the cluster could be Vietnam-aligned (targeting opposition or border-region entities) rather than China-aligned, though the more dominant assessment treats Vietnamese-language lures as standard regional tradecraft by a China-aligned operator. No formal government attribution has been issued by any state.

The "China-aligned" framing reflects the dominant Chinese-vendor and Group-IB-adjacent assessment but should be treated as suspected rather than confirmed.

Motivations
espionage, intelligence_gathering, geopolitical_collection, government_collection, military_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)54/60 · 90%
Analytics (MITRE CAR)24/60 · 40%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MICROSOFT365 C2 ABUSEMSHTAMSI ATTACHMENT DROPPERSSTEP1.EXE STAGED LOADERSTEP2.EXE STAGED LOADER

CVEs Exploited

3
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin