Ink Dragon's Relay Network and Stealthy Offensive Operation
Dec. 21, 2025, 7:32 p.m.
Description
Check Point Research has identified a new wave of attacks by the Chinese threat actor Ink Dragon, targeting government entities in Europe, Southeast Asia, and South America. The actor builds a victim-based relay network using a custom ShadowPad IIS Listener module, turning compromised servers into active nodes within a distributed mesh. Ink Dragon continues to exploit IIS misconfigurations for initial access and is evolving its operations with new TTPs and tools, including a new variant of FinalDraft malware. The group's campaigns combine software engineering, disciplined operational playbooks, and the use of platform-native tools to blend into normal enterprise telemetry, making their intrusions both effective and stealthy.
Tags
Date
- Created: Dec. 16, 2025, 2:57 p.m.
- Published: Dec. 16, 2025, 2:57 p.m.
- Modified: Dec. 21, 2025, 7:32 p.m.
Indicators
- e2f6e722c26e19b76396c2502cacf2aaceaaa1486865578c665ebf0065641ffa
- 7efe5c1229178c1b48f6750c846575e7f48d17ea817997bd7acba0e5ecf1e577
- a86e72ca58de6d215a59ae233963eaea27fe47ef0c9f43938e27339df4a86732
- 2b57deb1f6f7d5448464b88bd96b47c5e2bd6e1c64c1b9214b57c4d35a591279
- 2e84ea5cef8a9a8a60c7553b5878a349a037cffeab4c7f40da5d0873ede7ff72
- f9dd0b57a5c133ca0c4cab3cca1ac8debdc4a798b452167a1e5af78653af00c1
- 36f00887f6c0af63ef3c70a60a540c64040b13a4209b975e96ce239e65548d4a
- f094ff83d4b7d06bc17b15db7d7dc0e622778b0eda71e8fc9fdf7db83c460426
- f438ca355e6888c4c9cd7287b22cfe5773992ef83f0b16e72fb9ae239d85586c
- 866fde351251092fb5532e743459ba80968cd5516cce813c8755467f5e8a47a1
- 809ddcbb64d6f2ccc4a8909068da60e6ea8b3ebd9c09dd826def0e188c7a2da2
- ecf0fbd72aac684b03930ad2ff9cdd386e9c13ddf449f27918f337dc8963590e
- b4a53f117722fb4af0a64d30ec8aa4c4c82f456e3d2a5c5111c63ce261f3b547
- d88115113e274071b03a3b4c1da99eaea7b8d94adf833dfd26943af0a6d78b4d
- c305b3b3f9426d024cdd262497a5d196264397bfed445705759d0a793a58fe6e
- 188ab2d68f17ecf08a7a4cfc6457c79b0a5117b3277352a7371a525416129114
Additional Informations
- Government and administrations