Really nice write-up from the GroupIB team on an #APT they are calling #DarkPink (aka #SaaiwcGroup) targeting #APAC victims.

The lateral movement technique via WMI Filter/Consumer to USB is interesting.

#DFIR #ThreatIntel

https://blog.group-ib.com/dark-pink-apt

Dark Pink

New APT hitting Asia-Pacific, Europe that goes deeper and darker

Group-IB