216.73.216.6

The stealthy trilogy of PurpleInk, InkBox and InkLoader

· Published 30/05/2024 15:12 · Modified 30/05/2024 15:32

Export JSON

Essential information

Published
30/05/2024 15:12
Modified
30/05/2024 15:32
Tags
2024-05-30 inkloader purpleink
Related entities
4 observables, 1 intrusion sets (apt), 20 techniques (mitre), 4 malware, 4 others

Description

A new data theft campaign, attributed to an advanced persistent threat actor dubbed 'LilacSquid', has been active since at least 2021. The campaign targets diverse victims across various sectors in the United States, Europe, and Asia. It employs MeshAgent, an open-source remote management tool, and a customized version of QuasarRAT called '' as primary implants after compromising vulnerable internet-facing application servers. LilacSquid leverages vulnerabilities and compromised RDP credentials to deploy tools like MeshAgent, SSF, , and two malware loaders called 'InkBox' and '' for establishing long-term access and data exfiltration.

External references