logo

LilacSquid APT Employs Open Source Tools, QuasarRAT

ID: 8dc51687-d539-57bc-9313-796b42fa7c8e

STIX ID: report--8dc51687-d539-57bc-9313-796b42fa7c8e

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-05-31

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Cisco Talos researchers attribute a previously unknown APT dubbed LilacSquid to targeted data-exfiltration campaigns spanning the US, Europe, and Asia. LilacSquid gains initial access by exploiting public vulnerabilities and stolen RDP credentials, uses open-source remote management (MeshAgent) and tunneling (SSF), and employs InkLoader to deploy and run a heavily obfuscated custom QuasarRAT variant called PurpleInk to maintain long-term access and steal data; tactics overlap with North Korean groups such as Andariel/Lazarus.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.