UAT-4820

2024-05-30 • Cisco TalosLilacSquid: The stealthy trilogy of PurpleInk, In…

UAT-4820 is Cisco Talos’ designation for the espionage actor it also calls LilacSquid. Talos described the cluster in May 2024 after observing compromises dating from at least 2021 against organizations in pharmaceuticals, oil and gas, and technology sectors in the United States, Europe, and Asia. The actor gained access by exploiting vulnerable public-facing applications or by using compromised remote-desktop credentials. It then deployed open-source tools such as MeshAgent and customized versions of QuasarRAT, before introducing a proprietary loader named InkLoader and the PurpleInk remote-access trojan. The tradecraft showed overlap with North Korean activity tracked as Andariel, including use of the same SOCKS proxy and tunneling tool. UAT-4820’s small victim set, deliberate infrastructure, multiple access routes, tunneling, system discovery, and layered malware deployment indicate a patient campaign focused on maintaining covert access to strategically valuable organizations.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster