#PurpleInk

Malware/Tool

2024-05-30 • LilacSquid: The stealthy trilogy of PurpleInk, InkBox and InkLoader

PurpleInk is a customized QuasarRAT variant used as a primary implant by the LilacSquid threat actor in a suspected data-theft campaign active since at least 2021. LilacSquid deployed it after exploiting vulnerable internet-facing application servers or using compromised Remote Desktop Protocol credentials. Infection chains also used the open-source MeshAgent remote-management tool and SSF tunneling software for secondary access and exfiltration. Victims included US software organizations serving research and industrial sectors, European energy organizations, and an Asian pharmaceutical organization.

Tagged Reports

« Back