Dark Pink, a new Advanced Persistent Threat (APT) group that has been operative since mid-2021, is targeting Asian governments and military formations, according to a Cabinet Division assessment.
The APT organisation employs advanced tactics, strategies, and processes that call for proactive cyber security surveillance in government and military environments.
According to the advice, Dark Pink used phishing emails and sophisticated attacks on email networks in recent attacks on the Malaysian Armed Forces (MAF).
In Pakistan, the group is also active in attacking government institutions and military installations.
Dark Pink exploits systems by methods such as USB infection and DLL exploitation. Phishing emails are the most common source of compromise (unauthorized penetration and access).
Cabinet Meeting
The Cabinet Division has instructed government employees not to read unknown or questionable emails, links, or attachments.
Before downloading any attachments, use an email service provider’s anti-virus scanner, and keep all apps and operating systems up to date. (mobile and PC).
It has advised utilising reputable and up-to-date anti-virus/anti-malware software. A thorough examination of application permissions, system operating processes, and storage utilisation on a regular basis.
Separate and difficult passwords for each system, mobile device, social media account, financial and mailing account, and so on.
According to the advise, government workers should never utilise personal accounts on official systems and should instead use multi-factor authentication (MFA)/two-factor authentications wherever possible.
It has also requested that personal information and credentials not be shared with unauthorised/suspicious users, websites, or applications.
It has been requested that URLs be typed into the browser rather than clicked on. Furthermore, the advise recommends that you always open websites with HTTPS and avoid visiting HTTP websites.
The Cabinet Division has directed administrators in government offices and divisions to limit inbound traffic and user permissions to the greatest extent possible by hardening systems at the OS, BIOS, and application levels.
It has also requested that unauthorized USB and storage media be blocked by hardening and that the USB be formatted every time before use to ensure that no virus is spread from one system to the next, as well as that networks be monitored for file hashes, file locations, logins, and failed login attempts.
The alert advises administrators to utilise reputable anti-virus, firewall, IPS/lDS, and SIEM solutions, as well as separate servers/routing for offline and online networks.
It has also requested that internet access be granted to certain users on a need-to-know basis and that data usage/application permissions be restricted.
It has advised that software and documents be verified before downloading using a digital code-signing mechanism.
The advise has requested that MFA be included in email system administrator controls as well as other important systems.
It has advised that essential data be backed up on a regular basis, in addition to changing administrator passwords and patching and updating all operating systems, programs, and other technical equipment.
According to Albert Priego of Group-IB, government and military organisations in the Asia-Pacific area are being targeted by a hitherto undisclosed advanced persistent threat (APT) actor.
In a study published with The Hacker News, the Singapore-based company stated that it is tracking the continuing effort known as Dark Pink and has ascribed seven successful attacks to the antagonistic collective between June and December 2022.
The majority of the attacks have targeted military and government ministries and agencies, as well as religious and non-profit organisations in Cambodia, Indonesia, Malaysia, the Philippines, Vietnam, and Bosnia and Herzegovina, with one failed intrusion reported against an unnamed European state development body based in Vietnam.
The threat actor is thought to have begun operations in mid-2021, but the attacks began barely a year later, utilising a never-before-seen specialised toolkit designed to steal vital information from vulnerable networks.
To read our latest blog on “Data from Institute of Space Technology is leaked by hackers,” click here
