#PurpleInk
Malware/Tool
2024-05-30 • LilacSquid: The stealthy trilogy of PurpleInk, InkBox and InkLoader
PurpleInk is a customized QuasarRAT variant used as a primary implant by the LilacSquid threat actor in a suspected data-theft campaign active since at least 2021. LilacSquid deployed it after exploiting vulnerable internet-facing application servers or using compromised Remote Desktop Protocol credentials. Infection chains also used the open-source MeshAgent remote-management tool and SSF tunneling software for secondary access and exfiltration. Victims included US software organizations serving research and industrial sectors, European energy organizations, and an Asian pharmaceutical organization.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days