LilacSquid is an APT actor targeting a variety of industries worldwide since at least 2021. They use tactics such as exploiting vulnerabilities and compromised RDP credentials to gain access to victim organizations. Their post-compromise activities involve deploying MeshAgent and a customized version of QuasarRAT known as PurpleInk to maintain control over infected systems. LilacSquid has been observed using tools like Secure Socket Funneling for data exfiltration.
Executive Summary
LilacSquid is an APT group active since at least 2021, targeting multiple industries globally using exploitation of vulnerabilities, RDP credentials, and custom malware. They deploy MeshAgent and PurpleInk (a modified QuasarRAT) for persistence, coupled with Secure Socket Funneling for data exfiltration. Their operations suggest a focus on long-term access and intelligence collection.
Goals & Targeting
LilacSquid's strategic objectives likely revolve around sustained access to target networks for intelligence gathering or data exfiltration. By targeting a wide range of sectors, they may aim to maximize operational flexibility and avoid sector-specific detection. Their use of compromised RDP credentials and vulnerability exploitation suggests a focus on organizations with outdated security postures, particularly those in industries with high-value data assets. While their precise motivations remain unclear, the deployment of custom malware and the absence of ransom demands imply a possible espionage or state-sponsored nexus.
Enhanced Description
LilacSquid, an unidentified APT actor, has been targeting organizations across various sectors since 2021. Their initial access often relies on exploiting unpatched vulnerabilities or compromised RDP credentials, indicating a preference for low-and-slow infiltration methods. Once inside networks, the group deploys MeshAgent—a remote access tool—and a customized QuasarRAT variant named PurpleInk to maintain control and execute commands. Secure Socket Funneling is leveraged to securely exfiltrate stolen data, demonstrating a capacity for advanced operational security. Although no specific aliases or known motivations have been reported, the group's focus on persistence and data harvesting suggests an interest in long-term surveillance or intellectual property theft. The lack of public attribution or detailed campaign reporting highlights the need for further analysis to contextualize their activities within broader threat landscapes.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
LilacSquid's campaigns exhibit a preference for stealth and adaptability, using a combination of exploitation, credential theft, and custom malware to establish and maintain access. Their operational tempo suggests a focus on prolonged infiltration rather than rapid disruption. Notable past operations have involved targeting unspecified industries, with no publicly documented incidents or compromises linked to specific victims. The group's reliance on RDP and vulnerability exploitation indicates a focus on organizations with weak perimeter defenses.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on observed TTPs and tool usage, with moderate confidence due to limited public reporting on LilacSquid's activities. Gaps include unconfirmed details about first/last seen dates, specific targeted sectors, and the group's potential affiliations or motivations. Further analysis is required to validate the MITRE technique mappings and refine the actor's strategic objectives.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics