{
  "Event": {
    "analysis": "1",
    "date": "2026-06-04",
    "extends_uuid": "",
    "info": "[Threat Intel] Latest goon squad to use fake helpdesk calls to steal creds",
    "protected": false,
    "publish_timestamp": "1781219596",
    "published": true,
    "threat_level_id": "3",
    "timestamp": "1781219595",
    "uuid": "8ca1d989-09c8-453d-a9ab-960c76b97f27",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#10003d",
        "local": false,
        "name": "rectifyq:sub-category=\"TA-profile\"",
        "relationship_type": ""
      },
      {
        "colour": "#f1dfed",
        "local": false,
        "name": "rectifyq:TA-category=\"Cybercrime\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780657211",
        "to_ids": false,
        "type": "link",
        "uuid": "079ef6ee-1007-483d-8bb5-0bb8572423d9",
        "value": "https://www.theregister.com/cyber-crime/2026/06/04/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds/5251434",
        "Tag": [
          {
            "colour": "#6b003a",
            "local": true,
            "name": "workflow:todo=\"create-missing-misp-galaxy-cluster\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780657211",
        "to_ids": false,
        "type": "text",
        "uuid": "2ebc7592-5c92-4196-8b41-a9429825d56c",
        "value": "A new extortion group called Pink, tracked as cluster CL-CRI-1147, employs voice phishing and fake IT helpdesk impersonation to compromise organizations. The gang steals employee credentials, bypasses multi-factor authentication, and exfiltrates data from cloud storage platforms like SharePoint and OneDrive. Pink threatens to leak stolen information unless ransom demands are met, setting 72-hour deadlines. The group's data-leak site launched on May 31, 2026. This approach mirrors tactics popularized by Lapsus$, Scattered Spider, and ShinyHunters. Incident responders link Pink to The Com, a loosely connected network of English-speaking hackers and extortionists. Attackers use compromised victim accounts and internal Teams messages for extortion communications, reusing domains across multiple targets."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780657211",
        "to_ids": false,
        "type": "text",
        "uuid": "b63d5f02-710e-4782-ba97-8077a591b68b",
        "value": "Name: Latest goon squad to use fake helpdesk calls to steal creds\nAuthor: AlienVault\nAdversary: Pink\nTags: [\"mfa bypass\", \"the com\", \"credential phishing\", \"social engineering\", \"vishing\", \"helpdesk impersonation\", \"extortion\", \"cloud data theft\"]\nTgtd countries: []\nMlwr families: []\nAttack_ids: []\nIndustries: []"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781211910",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "148c3a6f-f235-478d-8a29-1a2be7258731",
        "value": "Pink",
        "Tag": [
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:threat-actor=\"UNC6671\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "hosted phishing domain",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781216248",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "bc4cee98-82c3-4a18-889f-a933cdc111ab",
        "value": "185.178.208.153",
        "Tag": [
          {
            "colour": "#a4a64f",
            "local": false,
            "name": "asn:asn=\"57724\"",
            "relationship_type": ""
          },
          {
            "colour": "#2a74c4",
            "local": false,
            "name": "asn:as-owner=\"DDOS-GUARD\"",
            "relationship_type": ""
          },
          {
            "colour": "#fdd220",
            "local": false,
            "name": "asn:as-country=\"RU\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"russia\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "phishing domain",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781216269",
        "to_ids": true,
        "type": "domain",
        "uuid": "d83558d0-a1f7-48a9-8478-d3b7092a073a",
        "value": "deploypasskey.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "residential proxy IP responsible for extortion email creation",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781216291",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "463b2cd9-a94c-4304-a245-a1989a4c656a",
        "value": "96.232.20.66",
        "Tag": [
          {
            "colour": "#e61cad",
            "local": false,
            "name": "asn:asn=\"701\"",
            "relationship_type": ""
          },
          {
            "colour": "#3fe11e",
            "local": false,
            "name": "asn:as-owner=\"UUNET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "phishing domain",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781216313",
        "to_ids": true,
        "type": "domain",
        "uuid": "89608f8b-ccb3-494d-bfd4-c20a6a95c78e",
        "value": "passkeyadd.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "phishing domain",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781216334",
        "to_ids": true,
        "type": "domain",
        "uuid": "67e6ffe4-928b-45fd-93d2-4cee97e8582e",
        "value": "passkeydeploy.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "accessed compromised accounts",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781216355",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "50f8b6e1-3306-407c-9f3f-d5f2c69e72ce",
        "value": "172.93.100.252",
        "Tag": [
          {
            "colour": "#5ba9b8",
            "local": false,
            "name": "asn:asn=\"23470\"",
            "relationship_type": ""
          },
          {
            "colour": "#91a53d",
            "local": false,
            "name": "asn:as-owner=\"RELIABLESITE\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ]
  }
}