Home Cloud Security New Pink Hackers Attack Enterprises for Cloud Storage Credentials

New Pink Hackers Attack Enterprises for Cloud Storage Credentials

0
Pink Hackers Steal Credentials
Pink Hackers Steal Credentials

A highly sophisticated cyber extortion brand known as “Pink” has recently emerged, targeting enterprise organizations with aggressive social engineering campaigns.

Tracked by threat intelligence researchers under the name CL-CRI-1147, this newly identified group represents a growing trend of specialized, human-driven extortion operations.

Pink officially launched its dedicated dark web leak site on May 31, 2026, signaling its readiness to shame corporate victims publicly, as reported by Palo Alto Networks.

The group focuses heavily on harvesting credentials for cloud storage services to compromise enterprise productivity applications.

By gaining unauthorized access to these environments, the attackers exfiltrate sensitive data to leverage in high-pressure ransom demands.

Pink Hackers Steal Credentials

Pink operates as an affiliate of “The Com,” a decentralized cybercriminal ecosystem notorious for weaponizing advanced social engineering techniques.

Unlike traditional ransomware operators that rely on exploiting software zero-days or automated malware, Pink relies entirely on human manipulation to bypass security perimeters.

Pink Hackers Steal Credentials (Source: linkedin)
Pink Hackers Steal Credentials (Source: linkedin)

The group’s primary initial access vector is vishing, or voice phishing, aimed directly at unsuspecting corporate employees.

Threat actors carefully research organizational charts on professional networking sites to identify prime administrative targets.

They then initiate phone calls while actively spoofing corporate caller ID systems to make the communication appear authentic.

During these targeted phone calls, the attackers confidently masquerade as internal IT helpdesk personnel or technical support staff.

Pink Hackers Steal Credentials (Source: linkedin)
Pink Hackers Steal Credentials (Source: linkedin)

They create a sense of urgency, claiming there is an immediate issue with the employee’s account, payroll access, or a mandatory security update.

The goal is to trick the victim into navigating to a malicious, look-alike login portal controlled entirely by the threat actors.

Once the employee enters their corporate username and password, the attackers capture the credentials in real-time. This hands-on approach allows hackers to actively monitor the login process and adapt to security prompts in real time.

Bypassing Multi-Factor Authentication (MFA) is a critical component of Pink’s initial access strategy. If the enterprise uses standard MFA protocols, attackers prompt the user to approve the login request on their mobile device.

In other instances, they will playfully or aggressively convince the employee to provide the one-time passcode over the phone verbally.

The threat actors may also employ MFA fatigue techniques, flooding the victim’s device with approval requests until the frustrated employee finally accepts one.

Once the prompt is approved, the attackers establish a fully authenticated session within the corporate network.

With initial access secured, Pink threat actors rapidly pivot into the victim’s enterprise cloud infrastructure.

They specifically target high-value cloud environments, such as AWS and Azure, as well as productivity suites like Microsoft 365 and Google Workspace.

Instead of deploying ransomware payloads to encrypt the internal network, the group operates solely on a data-theft extortion model.

They quietly siphon massive volumes of proprietary company data, financial records, client databases, and confidential internal communications.

This silent exfiltration process enables the attackers to maintain persistence and steal critical data for weeks before security teams detect the anomaly.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here