Experts warn that Chinese “Ink Dragon” hackers are expanding their reach to European governments


  • Ink Dragon campaign hacks European governments by exploiting misconfigured IIS and SharePoint servers
  • The group uses its FinalDraft backdoor to mix C2 traffic with normal Microsoft cloud activity
  • Dozens of government and telecommunications entities worldwide were converted into relay hubs for further operations

Ink Dragon, a known Chinese state-sponsored threat actor, has extended its reach to European governments by using misconfigured devices for initial access and establishing persistence by interfering with regular traffic, experts have warned.

A report by cyber security researchers Check Point Software claims that the attackers are using Microsoft IIS and SharePoint servers as relay nodes for future operations.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top