logo

LilacSquid: The stealthy trilogy of PurpleInk, InkBox and InkLoader

ID: 92779fac-81ea-531d-80a5-28051d343d07

STIX ID: report--92779fac-81ea-531d-80a5-28051d343d07

Feed Name: Cisco Talos

Threat Score
85/100

Date Published: 2024-05-30

Date Updated: 2026-04-27

Author: Asheer Malhotra

...
...

**Executive Summary:** Cisco Talos attributes a long-running (since at least 2021) data-theft campaign to the APT dubbed “LilacSquid,” which compromises internet-facing application servers and uses stolen RDP credentials to deploy MeshAgent, Secure Socket Funneling (SSF), and a customized QuasarRAT called PurpleInk (alongside loaders InkBox/InkLoader) to establish persistent remote access and exfiltrate data across victims in the United States, Europe, and Asia; the report provides detailed infection chains, RAT capabilities, IOCs, and detection/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.