LilacSquid
· Published 21/12/2025 05:07 · Modified 21/12/2025 05:07
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 05:07
- Modified
- 21/12/2025 05:07
- Updated at
- 21/12/2025 05:07
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 2 reports, 35 attack patterns (mitre), 4 malware, 3 sectors, 2 countries, 9 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (2)
-
20 MITREs 1 Malware 9 Observables 1 APTPublished 05/08/2024 08:43 · Modified 05/08/2024 09:05
-
20 MITREs 4 Malwares 4 Observables 1 APTPublished 30/05/2024 15:12 · Modified 30/05/2024 15:32
Attack patterns (MITRE) (35)
-
T1086 uses
-
T1127 usesTrusted Developer Utilities Proxy Execution
-
T1567 usesExfiltration Over Web Service
-
T1041 usesExfiltration Over C2 Channel
-
T1211
-
T1008 usesFallback Channels
-
T1190 usesExploit Public-Facing Application
-
T1518 usesSoftware Discovery
-
T1057 usesProcess Discovery
-
T1068 usesExploitation for Privilege Escalation
-
T1059 usesCommand and Scripting Interpreter
-
T1005 usesData from Local System
-
T1543 usesCreate or Modify System Process
-
T1105 usesIngress Tool Transfer
-
T1547 usesBoot or Logon Autostart Execution
-
T1095 usesNon-Application Layer Protocol
-
T1070 usesIndicator Removal
-
T1043 usesCommonly Used Port
-
T1087 usesAccount Discovery
-
T1012 usesQuery Registry
-
T1083 usesFile and Directory Discovery
-
T1216
-
T1055 usesProcess Injection
-
T1021 usesRemote Services
-
T1082 usesSystem Information Discovery
-
T1132 usesData Encoding
-
T1219 usesRemote Access Tools
-
T1574 usesHijack Execution Flow
-
T1027 usesObfuscated Files or Information
-
T1053 usesScheduled Task/Job
-
T1048 usesExfiltration Over Alternative Protocol
-
T1078 usesValid Accounts
-
T1490 usesInhibit System Recovery
-
T1033 usesSystem Owner/User Discovery
-
T1064 usesScripting
Malware (4)
-
PurpleInk usesFamilyPublished 30/05/2024 15:12 · Modified 30/05/2024 15:12
-
MeshAgent usesFamilyPublished 02/09/2025 08:34 · Modified 02/09/2025 08:34
-
InkLoader usesFamilyPublished 30/05/2024 15:12 · Modified 30/05/2024 15:12
-
InkBox usesFamilyPublished 30/05/2024 15:12 · Modified 30/05/2024 15:12
Sectors (3)
- Pharmacy and drugs manufacturing targets
- Energy targets
- Technology targets
Countries (2)
- Israel targets
- United States of America targets
Indicators (9)
-
http://api.gupdate.net:443/agent.ashxindicates -
1134af27bea8518c62444a56f4bd4bcc95db40a9bb6132688cf31515da08b9aaindicates -
460acbb38b0bdb3d227de65010b1a323f448ec196860ce4979c0b8314763eb56indicates -
MeshAgent_Configindicates -
MeshAgent_ELFindicates -
3840acb15880f6cb0a77347d4a3893c5a3fbfcc2167bd5e3f86e2ce0f7cdbf19indicates -
2eb9c6722139e821c2fe8314b356880be70f3d19d8d2ba530adc9f466ffc67d8indicates -
api.gupdate.netindicates -
gupdate.netindicates