Lilac Squid

2024-05-30 • Cisco TalosLilacSquid: The stealthy trilogy of PurpleInk, In…

LilacSquid is an espionage-motivated threat actor named and publicly disclosed by Cisco Talos in May 2024 after Talos traced its activity to at least 2021. Talos also tracks the cluster as UAT-4820 and assessed that it sought long-term access for data theft. Confirmed victims included technology organizations serving research and industrial customers in the United States, a European energy organization, and an Asian pharmaceutical organization, suggesting broad collection interests rather than one industry focus. LilacSquid gains entry by exploiting internet-facing applications or using compromised remote-desktop credentials. It then deploys the legitimate MeshAgent remote-management utility, Secure Socket Funneling for tunneling, and custom malware including InkBox, InkLoader, and PurpleInk. PurpleInk, a heavily modified QuasarRAT, supports system discovery, file management and exfiltration, command execution, remote shells, and proxy connections. Talos noted tactical overlap with North Korean groups but did not present that overlap as definitive attribution.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster