logo

Chinese Ink Dragon Group Hides in European Government Networks

ID: 44a7ed73-dd39-52b2-890a-c4b95945f53c

STIX ID: report--44a7ed73-dd39-52b2-890a-c4b95945f53c

Feed Name: Infosecurity Magazine (News)

Threat Score
88/100

Date Published: 2025-12-17

Date Updated: 2026-04-22

...
...

Check Point warns that China-linked Ink Dragon is exploiting misconfigured public-facing servers (IIS, SharePoint) in European government networks to quietly gain domain-level access, harvest credentials, move laterally via RDP, and convert compromised servers into relay nodes using a customized IIS module and the FinalDraft backdoor; the activity expands previous campaigns in Asia and South America and overlaps with other advanced actors like RudePanda, demonstrating how single unpatched weaknesses enable multiple nation-state operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.