LilacSquid Strikes: New Cyber Espionage Group Targets US, Europe, and Asia
LilacSquid, a new cyber espionage threat actor, has been targeting sectors in the U.S., Europe, and Asia since 2021. They use tools like MeshAgent and PurpleInk for long-term data theft. Cisco Talos researcher Asheer Malhotra notes similarities with North Korean APT groups, including tactics and tools.

Hot Take:
Move over Squid Game! LilacSquid is the new villain in town, and it’s not here to play games—unless your data is up for grabs. With a penchant for espionage and a toolbox that would make a Swiss Army knife blush, this cyber-squid is spreading its tentacles across the globe. Time to batten down the hatches and sharpen those firewalls, people!
Key Points:
- New cyber espionage threat actor named LilacSquid targets multiple sectors globally.
- Campaign aims for long-term access to victim organizations to steal data.
- Utilizes open-source tools and custom malware like PurpleInk and InkLoader.
- Methods include exploiting known vulnerabilities and compromised RDP credentials.
- Shares tactics with North Korean APT groups, including the infamous Lazarus Group.
Already a member? Log in here