Dark Pink is an advanced persistent threat (APT) group that emerged in mid-2021, with activity surging in mid-to-late 2022. The group is assessed with moderate confidence to be of Southeast Asian origin, with some researchers alleging links to the Vietnamese state-sponsored threat actor OceanLotus. Their primary motivation is corporate espionage, focused on stealing sensitive documents, capturing audio from compromised devices, and exfiltrating data from messenger applications. Dark Pink distinguishes itself through its deployment of an almost entirely custom toolkit and the use of unconventional techniques, such as infecting USB devices and leveraging Event Triggered Execution: Change Default File Association. The group is also known as Saaiwc Group by Chinese cybersecurity researchers.