Ink Dragon Cyber Attacks Target Governments Using FINALDRAFT Malware
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Ink Dragon, a cyber threat actor associated with China, has intensified its focus on government targets in Europe since July 2025, while continuing operations in Southeast Asia and South America. This group, also referred to as Jewelbug, has been active since at least March 2023 and is tracked by Check Point Research under the name Ink Dragon.
The group’s tactics involve leveraging advanced malware, including FINALDRAFT, which can infect both Windows and Linux systems, and ShadowPad, a backdoor that enhances their command-and-control capabilities. Their operations have been linked to several dozen victims, including government and telecommunications organizations across multiple continents.
Ink Dragon’s attack methods include exploiting vulnerabilities in internet-exposed web applications to deploy web shells, which facilitate further payload delivery, such as VARGEIT and Cobalt Strike beacons. These techniques enable lateral movement, data exfiltration, and persistent access to compromised networks.
Notably, the group has utilized predictable ASP.NET machine key values to execute ViewState deserialization attacks against IIS and SharePoint servers, turning these systems into part of their command infrastructure. This approach allows them to route traffic deeper into networks, creating a multi-layered attack structure.
In one instance, Ink Dragon exploited an idle RDP session belonging to a Domain Administrator, achieving SYSTEM-level access and enabling domain-wide control over the compromised environment. This illustrates the potential for significant escalation from a single breach.
The sophistication of Ink Dragon’s operations highlights the evolving landscape of cyber threats, where compromised hosts can serve as nodes in a larger, attacker-controlled network. This interconnectedness complicates incident response, as defenders must dismantle entire relay chains to mitigate the threat.
Organizations must recognize that intrusions can link multiple victims, necessitating a comprehensive approach to cybersecurity that includes monitoring for unusual activity and securing vulnerable systems.
Key Takeaways
- Regularly update and patch all software to protect against known vulnerabilities.
- Implement network segmentation to limit lateral movement in case of a breach.
- Monitor for unusual RDP sessions and enforce strict access controls.
- Conduct regular security audits to identify and remediate misconfigurations.
- Educate staff on recognizing phishing attempts and suspicious activity.
Key Terms & Concepts
- FINALDRAFT: In this article, FINALDRAFT refers to a backdoor malware capable of infecting both Windows and Linux systems.
- ShadowPad: ShadowPad is a backdoor used by cyber actors to enhance command-and-control capabilities within compromised networks.
- Ink Dragon: Ink Dragon is a cyber threat actor group linked to China, known for targeting government entities and employing sophisticated malware.
- ViewState deserialization: ViewState deserialization is a technique exploited by attackers to manipulate ASP.NET applications and gain unauthorized access.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.