Pink is a data extortion threat actor tracked as CL-CRI-1147 that emerged in 2026 and is assessed to be part of, or closely aligned with, the broader Com cybercriminal ecosystem. The group is associated with social-engineering-led intrusions rather than traditional ransomware deployment, and its tradecraft overlaps with extortion actors such as Scattered Spider, ShinyHunters, Lapsus$, and the BlackFile/Redact lineage. External assessments have suggested Pink may represent a rebrand or successor operation connected to Redact and BlackFile, but such lineage should be treated as an assessment rather than confirmed attribution. Pink primarily targets enterprise organizations, with observed victimology concentrated in the United States across healthcare, biotech, technology, SaaS, financial services, food and beverage, automotive, construction, and aviation sectors. Its operations focus on compromising Microsoft 365 and Okta-linked identities belonging to employees who can provide access to valuable cloud data stores and internal communications. The actor’s initial access model relies heavily on voice phishing and impersonation of internal IT or help-desk personnel. Operators contact employees by phone, direct them to phishing pages themed around Microsoft Entra ID or Okta, and harvest credentials, MFA factors, and authenticated sessions. A notable Pink lure involves fake Microsoft Entra passkey enrollment, in which victims are guided through a counterfeit registration workflow while the attackers use the captured authentication material to access the legitimate account and enroll attacker-controlled persistence. Reported phishing workflows have been tailored to different MFA methods, including TOTP, SMS one-time codes, and push-based number matching. Pink’s phishing infrastructure and kits are notably mature and evasive. Reported capabilities include dynamic branding to mimic the target organization, backend-controlled gating, heartbeat polling, anti-bot and anti-analysis checks, environment fingerprinting, passive human-interaction requirements, and logic intended to block cloud-hosted analysis systems, virtual machines, headless browsers, and other researcher environments. The actor has also been reported to reuse portions of phishing infrastructure across multiple targets while customizing subdomains and branding per victim. After account compromise, Pink rapidly searches for and exfiltrates sensitive data from cloud collaboration and storage platforms, especially SharePoint and OneDrive. The group is reported to favor legitimate platform functionality and built-in automation over conspicuous malware, enabling fast, low-friction collection that can blend with normal cloud activity. Pink then uses compromised corporate email accounts and internal Microsoft Teams messaging to deliver extortion demands, typically imposing a short deadline and threatening public release of stolen data through its leak site. Pink operates as a data-theft-and-extortion actor rather than an encryption-focused ransomware crew. Its methods reflect the broader shift toward identity-centric, malware-light intrusions that exploit trust in enterprise identity systems, help-desk processes, and cloud productivity platforms. Known aliases and tracking identifiers include Pink and CL-CRI-1147.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the brands that emerged after BlackFile’s collapse, providing ecosystem context around Helix.
Conducting vishing-assisted phishing and data extortion campaigns by impersonating IT staff, stealing Microsoft 365 credentials and MFA factors through fake Entra passkey enrollment flows, enrolling attacker-controlled passkeys, exfiltrating data from SharePoint and OneDrive, and sending extortion messages from compromised accounts.
Mentioned as a potential successor in the same data-extortion ecosystem discussed around Helix and BlackFile.
Successor brand emerging after BlackFile's shutdown and described as running the same data extortion playbook.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.