#InkBox

Malware/Tool

2024-05-30 • LilacSquid: The stealthy trilogy of PurpleInk, InkBox and InkLoader

InkBox is a custom malware loader used by LilacSquid in older stages of the PurpleInk deployment chain beginning in 2021. It reads encrypted content from a hardcoded file path on disk, decrypts an embedded executable assembly, and invokes that assembly's entry point within the InkBox process. The decrypted payload is PurpleInk, a heavily customized QuasarRAT implant used for long-term access and data theft. LilacSquid later replaced this in-process approach with the more modular InkLoader service, which starts PurpleInk as a separate process after access through compromised RDP credentials.

Tagged Reports

« Back