LilacSquid

First seen
2021-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
organization
Actor type
nation-state
Profile updated
2026-07-07 12:15:40

Targeted industries: defense-and-aerospace energy-and-utilities financial-services government-and-public-sector technology-and-telecommunications

Context

LilacSquid is an APT actor targeting a variety of industries worldwide since at least 2021. They use tactics such as exploiting vulnerabilities and compromised RDP credentials to gain access to victim organizations. Their post-compromise activities involve deploying MeshAgent and a customized version of QuasarRAT known as PurpleInk to maintain control over infected systems. LilacSquid has been observed using tools like Secure Socket Funneling for data exfiltration.

Reports & references

  • Cisco Talos — Lilacsquid (report)

External references