Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors LilacSquid

Description

LilacSquid is an APT actor targeting a variety of industries worldwide since at least 2021. They use tactics such as exploiting vulnerabilities and compromised RDP credentials to gain access to victim organizations. Their post-compromise activities involve deploying MeshAgent and a customized version of QuasarRAT known as PurpleInk to maintain control over infected systems. LilacSquid has been observed using tools like Secure Socket Funneling for data exfiltration.

AI Analysis

· 1 week ago

Executive Summary

LilacSquid is an APT group active since at least 2021, targeting multiple industries globally using exploitation of vulnerabilities, RDP credentials, and custom malware. They deploy MeshAgent and PurpleInk (a modified QuasarRAT) for persistence, coupled with Secure Socket Funneling for data exfiltration. Their operations suggest a focus on long-term access and intelligence collection.

Goals & Targeting

LilacSquid's strategic objectives likely revolve around sustained access to target networks for intelligence gathering or data exfiltration. By targeting a wide range of sectors, they may aim to maximize operational flexibility and avoid sector-specific detection. Their use of compromised RDP credentials and vulnerability exploitation suggests a focus on organizations with outdated security postures, particularly those in industries with high-value data assets. While their precise motivations remain unclear, the deployment of custom malware and the absence of ransom demands imply a possible espionage or state-sponsored nexus.

Enhanced Description

LilacSquid, an unidentified APT actor, has been targeting organizations across various sectors since 2021. Their initial access often relies on exploiting unpatched vulnerabilities or compromised RDP credentials, indicating a preference for low-and-slow infiltration methods. Once inside networks, the group deploys MeshAgent—a remote access tool—and a customized QuasarRAT variant named PurpleInk to maintain control and execute commands. Secure Socket Funneling is leveraged to securely exfiltrate stolen data, demonstrating a capacity for advanced operational security. Although no specific aliases or known motivations have been reported, the group's focus on persistence and data harvesting suggests an interest in long-term surveillance or intellectual property theft. The lack of public attribution or detailed campaign reporting highlights the need for further analysis to contextualize their activities within broader threat landscapes.

Key Capabilities

  • Exploitation of unpatched software vulnerabilities
  • Compromise of RDP credentials through phishing or brute-force attacks
  • Deployment of MeshAgent for remote administration
  • Customization of QuasarRAT (PurpleInk) for persistence and lateral movement
  • Use of Secure Socket Funneling for encrypted data exfiltration
  • Operational security practices to avoid attribution

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Exfiltration

ATT&CK Techniques

T1135.002 (RDP Brute Force)
T1210 (Exploit Public-Facing Application Vulnerability)
T1059.003 (Remote Desktop Protocol)
T1055 (Process Injection)
T1041 (Exfiltration over C2 Channel)
T1053 (scheduled task / job)

Software / Tooling

MeshAgent
PurpleInk (modified QuasarRAT)
Secure Socket Funneling

Campaigns & Victims

LilacSquid's campaigns exhibit a preference for stealth and adaptability, using a combination of exploitation, credential theft, and custom malware to establish and maintain access. Their operational tempo suggests a focus on prolonged infiltration rather than rapid disruption. Notable past operations have involved targeting unspecified industries, with no publicly documented incidents or compromises linked to specific victims. The group's reliance on RDP and vulnerability exploitation indicates a focus on organizations with weak perimeter defenses.

IOC Patterns

  • Exploitation of unpatched Windows vulnerabilities (e.g., SMB, RDP)
  • Deployment of MeshAgent and PurpleInk RATs
  • C2 traffic via Secure Socket Funneling (SSL/TLS-encrypted tunnels)
  • Lateral movement using stolen credentials
  • Custom payloads with obfuscation to evade detection

Recommended Actions

  • Patch known vulnerabilities, particularly in RDP and public-facing applications
  • Implement multi-factor authentication for RDP access
  • Monitor for unusual remote desktop activity and lateral movement patterns
  • Deploy endpoint detection tools to identify MeshAgent or PurpleInk behavior
  • Use network traffic analysis to detect Secure Socket Funneling (SSL/TLS anomalies)
  • Conduct regular employee training to prevent credential theft through phishing

Suggested Tags

APT
espionage
remote access
data exfiltration
custom malware

Confidence Assessment

The analysis is based on observed TTPs and tool usage, with moderate confidence due to limited public reporting on LilacSquid's activities. Gaps include unconfirmed details about first/last seen dates, specific targeted sectors, and the group's potential affiliations or motivations. Further analysis is required to validate the MITRE technique mappings and refine the actor's strategic objectives.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
Backdoor / C2
Data Exfiltration
espionage
remote access
data exfiltration
custom malware

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.