logo

Cyber Espionage Alert: LilacSquid Targets IT, Energy, and Pharma Sectors

ID: 4e0c5703-b7af-5fa8-ae10-fbe5fa0c414a

STIX ID: report--4e0c5703-b7af-5fa8-ae10-fbe5fa0c414a

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-05-30

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

LilacSquid is a previously undocumented cyber-espionage threat actor active since at least 2021, conducting a cross-regional data-theft campaign against IT, energy, and pharmaceutical sectors. The adversary uses exploited internet-facing vulnerabilities and compromised RDP credentials to establish long-term access, deploying MeshAgent and a custom Quasar-derived RAT (PurpleInk) via InkLoader/InkBox; recent variants simplify functionality to avoid detection. The campaign also uses SSF tunneling and shares multiple TTP overlaps with North Korean APTs such as Andariel/Lazarus.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.