Pink, tracked by Okta as O-UNC-066 and by Palo Alto Networks Unit 42 as CL-CRI-1147, is a financially motivated extortion threat actor associated with voice-phishing operations against enterprise Microsoft 365 environments. The actor has targeted organizations in the automotive, aviation, construction, food and beverage, healthcare, and technology sectors, with activity observed from April 2026 onward. Pink operates a data leak and extortion brand of the same name and appears primarily focused on data theft and extortion rather than software exploitation. Pink is notable for combining vishing with a manually operated, panel-controlled phishing framework that impersonates Microsoft Entra passkey enrollment. Operators call employees while posing as internal IT or security staff and direct them through a fraudulent enrollment workflow designed to capture Microsoft 365 credentials and MFA responses in real time. The phishing operation is interactive rather than fully automated: the operator adapts the flow to the victim’s authentication method, including SMS one-time codes, time-based one-time passwords, and push-based approvals with number matching. The kit also performs anti-analysis checks and uses legitimate Microsoft branding and remotely loaded content to increase credibility. A defining aspect of this activity is abuse of passkey enrollment rather than simple credential theft. Victims are led to believe they are registering a legitimate passkey for their own account, while the attacker simultaneously enrolls an attacker-controlled passkey on the victim’s Microsoft account. The workflow may include fake recovery-key steps using BIP-39-style seed phrases, apparently to distract the victim while the attacker completes enrollment. This technique can provide more durable account access than stolen passwords alone and supports rapid follow-on access to cloud data. Pink has been linked to post-compromise data theft from Microsoft cloud services such as SharePoint and OneDrive, followed by extortion through its leak site. Unit 42 has described the cluster as affiliated with The Com, a decentralized cybercriminal ecosystem known for social-engineering-heavy intrusions. High-confidence reporting consistently characterizes Pink as an extortion-focused actor that relies on IT impersonation, real-time credential interception, MFA manipulation, and attacker-controlled passkey registration to obtain and maintain access to victim Microsoft 365 accounts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a sophisticated vishing-led phishing campaign to steal Microsoft 365 credentials and enroll attacker-controlled passkeys on victim Microsoft accounts, with the apparent objective of data extortion.
Conducting cross-sector data extortion operations using vishing and phishing kits that impersonate corporate IT and mimic Microsoft 365 passkey enrollment to register attacker-controlled passkeys and take over victim accounts.
Conducting vishing-led phishing campaigns against Microsoft 365 users by calling victims, directing them to fake Microsoft Entra ID login pages, harvesting credentials in real time, and enrolling attacker-controlled passkeys for account takeover and data extortion.
Conducting voice-based phishing (vishing) campaigns against Microsoft 365 users to trick them into enrolling attacker-controlled Entra passkeys, enabling account takeover and follow-on data extortion attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.