Experts warn Chinese “Ink Dragon” hackers extend reach into European governments



  • Ink Dragon campaign breaches European governments by exploiting misconfigured IIS and SharePoint servers
  • The group uses its FinalDraft backdoor to blend C2 traffic with normal Microsoft cloud activity
  • Dozens of government and telecom entities worldwide were turned into relay nodes for further operations

Ink Dragon, a known Chinese state-sponsored threat actor, has extended its reach into European governments, using misconfigured devices for initial entry, and establishing persistence by blending with regular traffic, experts have warned.

A report from cybersecurity researchers Check Point Software claims the attackers are using Microsoft IIS and SharePoint servers as relay nodes for future operations.


https://cdn.mos.cms.futurecdn.net/DVYr26EgcJb68CRrjxuAW4-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img