The China-linked threat actor known as Ink Dragon, also tracked as Jewelbug, has intensified its cyberespionage operations against government and telecommunications organizations across Europe, Asia, and Africa. Recent campaigns have involved the compromise of internet-exposed web applications, such as misconfigured Microsoft IIS and SharePoint servers, to establish initial access. Once inside, the attackers deploy web shells and backdoors, including FINALDRAFT and NANOREMOTE, to facilitate command-and-control, lateral movement, and data exfiltration. The group has demonstrated advanced operational security by blending malicious activity with legitimate enterprise traffic, using platform-native tools, and leveraging compromised servers as relay nodes to expand their reach and maintain persistence.
Check Point Research and other security firms have observed that Ink Dragon's tactics include credential harvesting, the use of existing accounts for stealthy lateral movement, and the installation of implants that store sensitive data. The FINALDRAFT backdoor has been updated to better evade detection by mimicking Microsoft cloud activity and restricting its communications to business hours. The campaign has impacted several dozen victims, with the attackers focusing on long-term access and data theft while minimizing their operational footprint to avoid detection by defenders.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 said Check Point's findings aligned with its own intelligence and noted an increase in Ink Dragon activity in recent months. This served as external corroboration of the campaign's scale and tempo.
In mid-December 2025, Check Point's findings were published, detailing Ink Dragon's expansion into European government networks, use of relay-node infrastructure, and updated malware. The disclosure also highlighted stealthy post-exploitation tactics such as credential theft, lateral movement, and AD data exfiltration.
Check Point identified a second China-linked actor, REF3927 or RudePanda, in several overlapping victim networks. Researchers assessed overlap in access methods but found no evidence of direct operational coordination with Ink Dragon.
Check Point observed a new FINALDRAFT variant for Windows and Linux that abuses Outlook drafts and Microsoft Graph API for covert command and control. The malware blended with legitimate Microsoft cloud activity and supported long-term stealthy access.
After gaining access, Ink Dragon installed custom IIS modules, including a ShadowPad IIS Listener, to turn victim servers into relay nodes for command-and-control traffic. The mesh helped obscure the origin of operations and supported further intrusions against additional targets.
The espionage campaign affected several dozen victims across Europe, Asia, and Africa, including government and telecommunications organizations. Attackers exploited internet-exposed IIS, SharePoint, and ASP.NET ViewState weaknesses and misconfigurations for initial access.
Since July 2025, Ink Dragon increasingly targeted European government networks while continuing operations in Southeast Asia and South America. This was described as the first observed targeting of European networks by the group.
Check Point said the China-aligned cluster tracked as Ink Dragon, Jewelbug, Earth Alux, and REF7707 has been active since at least March 2023. Earlier operations focused on regions including Southeast Asia and South America before later expansion into Europe.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcecsoonline.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.