Chinese-based Ink Dragon Compromises Asia and South America into European Government Networks
ID: 29fe7334-78c5-5554-9769-0472f7924c44
STIX ID: report--29fe7334-78c5-5554-9769-0472f7924c44
Feed Name: cybersecurityNews.com
Ink Dragon, a Chinese espionage group, has methodically expanded operations from Southeast Asia and South America into European government networks, using stolen credentials, dormant administrative sessions, and exploitation of web server/SharePoint configuration weaknesses to gain initial access. The group employs advanced techniques—transforming compromised servers into relay nodes and using an updated FinalDraft backdoor that hides commands in Microsoft mailbox drafts—to maintain long-term, stealthy access and exfiltrate data, with overlap observed from other actors like RudePanda in the same environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
