New Nork-ish cyberespionage outfit uncovered after three years
ID: a7cd3d9f-c0f1-5b4c-b5b5-bfd951003829
STIX ID: report--a7cd3d9f-c0f1-5b4c-b5b5-bfd951003829
Feed Name: The Register (Security)
Cisco Talos researchers uncovered LilacSquid, an espionage-focused cybercrime/APT-like group active since 2021 that has successfully breached organizations across the US, Europe, and Asia; the group leverages web application exploits and stolen RDP credentials to deploy MeshAgent, a heavily customized QuasarRAT variant called PurpleInk, InkLoader, and proxy/tunneling tools (e.g., SSF) to maintain long-term access, exfiltrate sensitive data, and evade detection—tradecraft resembling DPRK-linked groups such as Lazarus/Andariel.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
