UAT-4820
2024-05-30 • Cisco Talos • LilacSquid: The stealthy trilogy of PurpleInk, In…
UAT-4820 is Cisco Talos’ designation for the espionage actor it also calls LilacSquid. Talos described the cluster in May 2024 after observing compromises dating from at least 2021 against organizations in pharmaceuticals, oil and gas, and technology sectors in the United States, Europe, and Asia. The actor gained access by exploiting vulnerable public-facing applications or by using compromised remote-desktop credentials. It then deployed open-source tools such as MeshAgent and customized versions of QuasarRAT, before introducing a proprietary loader named InkLoader and the PurpleInk remote-access trojan. The tradecraft showed overlap with North Korean activity tracked as Andariel, including use of the same SOCKS proxy and tunneling tool. UAT-4820’s small victim set, deliberate infrastructure, multiple access routes, tunneling, system discovery, and layered malware deployment indicate a patient campaign focused on maintaining covert access to strategically valuable organizations.
-
16
Related Actors
-
2
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster