logo

Chinese-based Ink Dragon Compromises Asia and South America into European Government Networks

ID: 29fe7334-78c5-5554-9769-0472f7924c44

STIX ID: report--29fe7334-78c5-5554-9769-0472f7924c44

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2025-12-18

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Ink Dragon, a Chinese espionage group, has methodically expanded operations from Southeast Asia and South America into European government networks, using stolen credentials, dormant administrative sessions, and exploitation of web server/SharePoint configuration weaknesses to gain initial access. The group employs advanced techniques—transforming compromised servers into relay nodes and using an updated FinalDraft backdoor that hides commands in Microsoft mailbox drafts—to maintain long-term, stealthy access and exfiltrate data, with overlap observed from other actors like RudePanda in the same environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.