Experts warn that Chinese ‘Ink Dragon’ hackers are expanding their influence over European governments


  • Ink Dragon campaign violates European governments by exploiting misconfigured IIS and SharePoint servers
  • The group uses its FinalDraft backdoor to mix C2 traffic with normal Microsoft cloud activity.
  • Dozens of government and telecommunications entities around the world have been transformed into relay nodes for other operations.

Ink Dragon, a well-known Chinese state-sponsored threat actor, has extended its reach to European governments, using misconfigured devices for initial entry and establishing persistence by blending in with regular traffic, experts have warned.

A report from cybersecurity researchers at Check Point Software claims that attackers are using Microsoft IIS and SharePoint servers as relay nodes for future operations.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top