Everything You Need to Know About LilacSquid

2024-06-13 Avertium

https://explore.avertium.com/resource/everything-you-need-to-know-about-lilacsquid

Thumbnail for Everything You Need to Know About LilacSquid

LilacSquid, also tracked as UAT-4820, is described as an espionage-focused actor active since at least 2021 against U.S. IT firms, European energy organizations, and Asian pharmaceutical companies. The report states that LilacSquid’s tactics resemble North Korean groups such as Andariel and Lazarus, while noting possible shared tools, infrastructure, or resources rather than proving attribution. Initial access comes through vulnerable internet-facing application servers or compromised RDP credentials, followed by deployment of MeshAgent, proxy and tunneling tools, and the InkLoader/PurpleInk implant chain. PurpleInk is a QuasarRAT-derived backdoor that collects system, process, drive, folder, and file information and supports remote shell and proxy communications. The DPRK relevance is the overlap with Andariel/Lazarus-style tradecraft, especially the use of remote management tooling, loaders, and long-term access for data theft.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN mphasis.com 2024-06-13 2024-06-13
IPv4 67.213.221.6 2024-05-30 2024-06-13
IPv4 45.9.251.14 2024-05-30 2024-06-13
IPv4 199.229.250.142 2024-05-30 2024-06-13
IPv4 192.145.127.190 2024-05-30 2024-06-13
IPv4 74.124.228.148 2023-09-12 2024-06-13

Related Actors

Related Reports

« Back