The Dark Pink APT threat actor has recently been linked to a new wave of attacks against government and military institutions in Southeast Asian countries, using the KamiKakaBot malware.
See also: Cerebral shared patient data with Meta, Google, TikTok

The Dark Pink group, also known as Saaiwc, was first detected by Group-IB earlier this year. Group-IB reported that the Dark Pink group uses custom tools such as TelePowerBot and KamiKakaBot to execute arbitrary commands and extract sensitive information.
Information indicates that the likely source of this malicious activity is in the Asia-Pacific region and that this issue has been ongoing since at least mid-2021. This year has seen an uptick in attacks from this threat actor with increased frequency and intensity.
“The latest attacks, which took place in February 2023, were almost identical to previous attacks,” Dutch cybersecurity firm EclecticIQ revealed in a new report published last week.
"The main difference in the February campaign is that the malware's obfuscation routine has been improved to better evade anti-malware measures."
See also: BlackMamba AI attack evades advanced EDR security solutions
Cybercriminals use social engineering lures, which include ISO image file in emails, to deliver their malware.
The ISO image contains an executable file (Winword.exe), a loader (MSVCR100.dll), and a disguised Microsoft Word file that is already loaded with the powerful KamiKakaBot payload.

The loader is designed to use the DLL, allowing it to secretly load the KamiKakaBot malware into Winword.exe's memory and bypass any security measures in place.
KamiKakaBot is designed to steal data stored in web browsers , execute remote code using Command Prompt (cmd.exe) , and use evasion strategies to blend into its environment while avoiding detection.

Cybercriminals deploy malicious modifications to Windows registry keys, exploiting the Winlogon Helper library, in order to establish a permanent presence on their target computer. They then upload all the collected data into an encrypted ZIP, which is then securely sent via the Telegram bot.
See also: Medusa ransomware targets companies around the world
"Using legitimate web services as command-and-control (C2) servers, such as Telegram, remains the number one choice for diverse threat actors, ranging from regular cybercriminals to advanced threat actors," the company said.
"It is highly likely that the Dark Pink APT group are espionage-oriented cyber actors who have specifically targeted relations between ASEAN states and European states in order to create phishing campaigns during February 2023."
Information source: thehackernews.com
