logo

China's Ink Dragon hides out in European government networks

ID: bcb9e00b-7ca7-5a1b-a0f8-ab48e630c95a

STIX ID: report--bcb9e00b-7ca7-5a1b-a0f8-ab48e630c95a

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2025-12-16

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

### Executive summary Check Point researchers report that Chinese-linked espionage group Ink Dragon has expanded operations across government and telecommunications networks in Europe, Asia, and Africa by probing misconfigured Microsoft IIS/SharePoint servers, stealing credentials, deploying an updated FinalDraft backdoor that hides command traffic in mailbox drafts and limits noisy behavior, and converting public-facing servers into relay nodes to obscure origins of subsequent activity; researchers also observed unrelated RudePanda activity in some of the same networks and Amazon has warned of long-running relay-node campaigns attributed to the GRU.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.