Chinese Ink Dragon Group Hides in European Government Networks
ID: 44a7ed73-dd39-52b2-890a-c4b95945f53c
STIX ID: report--44a7ed73-dd39-52b2-890a-c4b95945f53c
Feed Name: Infosecurity Magazine (News)
Check Point warns that China-linked Ink Dragon is exploiting misconfigured public-facing servers (IIS, SharePoint) in European government networks to quietly gain domain-level access, harvest credentials, move laterally via RDP, and convert compromised servers into relay nodes using a customized IIS module and the FinalDraft backdoor; the activity expands previous campaigns in Asia and South America and overlaps with other advanced actors like RudePanda, demonstrating how single unpatched weaknesses enable multiple nation-state operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
