logo

New Nork-ish cyberespionage outfit uncovered after three years

ID: a7cd3d9f-c0f1-5b4c-b5b5-bfd951003829

STIX ID: report--a7cd3d9f-c0f1-5b4c-b5b5-bfd951003829

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-05-31

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Cisco Talos researchers uncovered LilacSquid, an espionage-focused cybercrime/APT-like group active since 2021 that has successfully breached organizations across the US, Europe, and Asia; the group leverages web application exploits and stolen RDP credentials to deploy MeshAgent, a heavily customized QuasarRAT variant called PurpleInk, InkLoader, and proxy/tunneling tools (e.g., SSF) to maintain long-term access, exfiltrate sensitive data, and evade detection—tradecraft resembling DPRK-linked groups such as Lazarus/Andariel.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.