#InkLoader
Malware/Tool
InkLoader is one of several access components deployed by the LilacSquid threat actor in a suspected data-theft campaign active since at least 2021. The campaign affected organizations in United States research and industrial software, European energy, and Asian pharmaceuticals. LilacSquid obtained access through exploitation of vulnerable public-facing applications or compromised Remote Desktop Protocol credentials, then deployed tools including MeshAgent, Secure Socket Funneling, InkLoader, and the PurpleInk implant. In the documented chain, exploitation caused a script to prepare working directories and retrieve MeshAgent; that agent contacted its command-and-control server, performed preliminary reconnaissance, and downloaded or activated further implants.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days