LilacSquid: The stealthy trilogy of PurpleInk, InkBox and InkLoader
2024-05-30 • Cisco Talos •
Cisco Talos tracks LilacSquid as an espionage-motivated APT active since at least 2021, compromising organizations in pharmaceuticals, oil and gas, and technology across Asia, Europe, and the United States. The campaign gains access through vulnerable internet-facing applications or stolen RDP credentials, then deploys MeshAgent, Secure Socket Funneling, InkLoader, and the PurpleInk implant, a heavily customized QuasarRAT variant. Talos notes overlap with North Korean APT tradecraft, including Andariel's reported use of MeshAgent and Lazarus use of proxy and tunneling tools for secondary access and exfiltration, but the activity is attributed here to LilacSquid. PurpleInk provides remote control, file operations, system discovery, reverse shell, and proxy capabilities, supporting long-term access and data theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 67.213.221.6 | 2024-05-30 | 2024-06-13 |
| IPv4 | 45.9.251.14 | 2024-05-30 | 2024-06-13 |
| IPv4 | 199.229.250.142 | 2024-05-30 | 2024-06-13 |
| IPv4 | 192.145.127.190 | 2024-05-30 | 2024-06-13 |
| HASH | 2eb9c6722139e821c2fe8314b356880… | 2024-05-30 | 2024-05-30 |