Is your threat intelligence timely? Is it directed towards your needs as a business? Does it provide indicators of compromise that are useful to your ability to defend your network? Those are all questions that each business engaged in the arena of threat intelligence should be asking themselves! Add to that tidbit, do you act when presented with applicable threat intelligence?
There are many sources of threat intelligence, but you must choose wisely, young Jedi, lest you be lost in a cloud of unfavorable intelligence, that in the end means nothing to the threats you actually face. It benefits companies when they actually spend the time and money to utilize the proper threat intelligence. Now, you might ask, where do I find such things?
One source is Unit42, a Palo Alto company. They have a website that provides up-to-date information. You can find it here: https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-06-03-Pink-Extortion-Brand-Activity.txt?utm_campaign=tti_pinkextortion
One of their most recent posts is concerning a new threat group, which they have named “Pink.” Pink is an extortion brand that utilizes vishing for initial access, which then leads to the extortion portion of their business model. And, make no mistake, these threat actors exist to make money! They have a business model, they have affiliates and they seek out vulnerable companies to attack.

Fig. 1: Unit 42 identification of threat actors
Your first step in threat intelligence is to ascertain if the particular threat geographically threatens you. So, according to the map above, this group is present in 3 or 4 states. So, ask yourself, is your business located in one of these states? Does this group present an active, existential threat to your business? If your business is in one of these states, then you should definitely be aware of the activity and the indicators of compromise.
Indicators of Compromise:
Phishing Domains:
– passkeyadd[.]com
– passkeydeploy[.]com
– deploypasskey[.]com
IP Addresses:
– 185[.]178.208[.]153 (hosted phishing domains)
– 172[.]93.100[.]252 (accessed compromised accounts)
– 96[.]232.20[.]66 (residential proxy IP responsible for extortion email creation)
User-agent Strings Observed During Exfiltration:
– Microsoft.Graph.Client/5.62.0
– python-requests/2.28.1
– python-requests/2.33.1
Above are the indicators of compromise provided by the Unit 42 intelligence group. Now, how can you use these?
- First, review the phishing domains. You can block them and then go back to review log files to see if they show up anywhere within your network or your email systems.
- Second, you have IP addresses. These can easily be blocked at a firewall. You can also use them to search for any possible internal connections to these Ips and learn if you have already been targeted.
- Finally, you have some “strings” provided. You can use these to search across your environment to see if they have been run in your environment.
Do not just accept any threat intelligence. Make it applicable to your environment and business organizations. Utilize good threat intelligence and then make the changes necessary to per-emptively protect your company.
Sources:
https://twitter.com/Unit42_Intel/status/2062216815967625558/photo/3
Leave a Reply