LilacSquid: The stealthy trilogy of PurpleInk, InkBox and InkLoader
ID: 92779fac-81ea-531d-80a5-28051d343d07
STIX ID: report--92779fac-81ea-531d-80a5-28051d343d07
Feed Name: Cisco Talos
**Executive Summary:** Cisco Talos attributes a long-running (since at least 2021) data-theft campaign to the APT dubbed “LilacSquid,” which compromises internet-facing application servers and uses stolen RDP credentials to deploy MeshAgent, Secure Socket Funneling (SSF), and a customized QuasarRAT called PurpleInk (alongside loaders InkBox/InkLoader) to establish persistent remote access and exfiltrate data across victims in the United States, Europe, and Asia; the report provides detailed infection chains, RAT capabilities, IOCs, and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
