LilacSquid: The stealthy trilogy of PurpleInk, InkBox and InkLoader

2024-05-30 Cisco Talos

https://blog.talosintelligence.com/lilacsquid/

Thumbnail for LilacSquid: The stealthy trilogy of PurpleInk, InkBox and InkLoader

Cisco Talos tracks LilacSquid as an espionage-motivated APT active since at least 2021, compromising organizations in pharmaceuticals, oil and gas, and technology across Asia, Europe, and the United States. The campaign gains access through vulnerable internet-facing applications or stolen RDP credentials, then deploys MeshAgent, Secure Socket Funneling, InkLoader, and the PurpleInk implant, a heavily customized QuasarRAT variant. Talos notes overlap with North Korean APT tradecraft, including Andariel's reported use of MeshAgent and Lazarus use of proxy and tunneling tools for secondary access and exfiltration, but the activity is attributed here to LilacSquid. PurpleInk provides remote control, file operations, system discovery, reverse shell, and proxy capabilities, supporting long-term access and data theft.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 67.213.221.6 2024-05-30 2024-06-13
IPv4 45.9.251.14 2024-05-30 2024-06-13
IPv4 199.229.250.142 2024-05-30 2024-06-13
IPv4 192.145.127.190 2024-05-30 2024-06-13
HASH 2eb9c6722139e821c2fe8314b356880… 2024-05-30 2024-05-30

Related Actors

Related Reports

« Back