China's Ink Dragon hides out in European government networks
ID: bcb9e00b-7ca7-5a1b-a0f8-ab48e630c95a
STIX ID: report--bcb9e00b-7ca7-5a1b-a0f8-ab48e630c95a
Feed Name: The Register (Security)
### Executive summary Check Point researchers report that Chinese-linked espionage group Ink Dragon has expanded operations across government and telecommunications networks in Europe, Asia, and Africa by probing misconfigured Microsoft IIS/SharePoint servers, stealing credentials, deploying an updated FinalDraft backdoor that hides command traffic in mailbox drafts and limits noisy behavior, and converting public-facing servers into relay nodes to obscure origins of subsequent activity; researchers also observed unrelated RudePanda activity in some of the same networks and Amazon has warned of long-running relay-node campaigns attributed to the GRU.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
