InkySquid is an advanced persistent threat (APT) that has been active since at least 2016 and targets government, military, defense contractors, and other organizations involved in national security. It uses a variety of techniques to evade detection by antivirus software and firewalls, including the use of stealth malware and custom-built tools for specific tasks such as fileless execution or memory injection. InkySquid has been linked to several high-profile attacks on government agencies in various countries, including the United States, China, Russia, and Iran.
Techniques, tactics and practices:
InkySquid uses a variety of techniques to evade detection by antivirus software and firewalls. These include using stealth malware, which is designed to hide from security tools and avoid being detected or removed; custom-built tools for specific tasks such as fileless execution or memory injection; exploiting vulnerabilities in operating systems and applications; conducting extensive research on target organizations before launching attacks; and employing sophisticated techniques such as spear phishing, watering hole attacks, and zero-day exploits. InkySquid also uses a variety of tools to maintain persistence within compromised networks, including rootkits, backdoors, and keyloggers.
