A long-running Chinese espionage group known as Ink Dragon has expanded its operations from Asia and South America into European government networks, according to new findings from Check Point Research (CPR).
The threat actor, active for years, is now using compromised servers as relay points to route traffic and commands to multiple victims, creating a hidden web of control that supports further attacks worldwide.
Security investigators noted that Ink Dragon’s campaigns often begin with simple configuration issues on public-facing servers such as Microsoft IIS or SharePoint.
Once inside, the attackers move discreetly, collecting local credentials and identifying active administrator sessions.
By reusing service accounts and using Remote Desktop Protocol (RDP), they quietly move through internal systems while appearing to be routine administrative activity.
After gaining domain-level privileges, Ink Dragon installs persistent backdoors, positions implants on high-value systems, and creates new methods for remote access.
These steps enable attackers to control the network long-term and integrate it into their broader operational infrastructure.
Turning Victims Into Attack Infrastructure
One of Ink Dragon’s most distinctive tactics is repurposing victims’ servers as communication relays. Using a custom IIS module, the group converts compromised servers into stealthy intermediary nodes that forward commands and stolen data between different targets.
This technique helps attackers conceal their origin and camouflage malicious activity as legitimate web traffic.
Recent campaigns revealed that a compromised system in one country might relay traffic for operations in another.

Each new breach strengthens the group’s distributed command network, making detection and attribution far more difficult for defenders.
CPR also observed Ink Dragon deploying a new version of its FinalDraft backdoor, a long-used remote access tool updated to blend in with Microsoft cloud services.
Instead of contacting external servers directly, this variant hides its command traffic within mailbox drafts, making the activity appear entirely ordinary in a corporate environment.
The latest version of FinalDraft adds controlled communication timing, allowing it to check in during work hours, efficient background data transfers, and detailed system profiling. These changes reflect a growing emphasis on stealth, cloud integration, and operational persistence.
In some compromised environments, CPR identified a second group, RudePanda, that was exploiting the same server flaw.
Although unrelated, the two actors operated within the same networks, demonstrating how unpatched vulnerabilities can attract multiple advanced threat groups.
Experts warn that defenders must look beyond isolated incidents. A breached system may already be part of a larger relay chain, meaning that complete remediation requires identifying and dismantling all connected nodes to evict the intruder.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates