You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
ink dragon
About this tag
The Ink Dragon tag covers a sophisticated cyber espionage cluster tracked by security researchers. Threads detail how Ink Dragon operators compromise IIS and SharePoint servers to build a ShadowPad relay network, turning victim infrastructure into command-and-control hubs. The group blends malicious traffic with legitimate HTTP behavior to evade detection. Discussions focus on the technical evolution of this threat, including its use of Windows server components for stealthy persistence and lateral movement. The tag is relevant for IT security professionals monitoring advanced persistent threats targeting enterprise Windows environments.
Check Point Research’s excavation of the Ink Dragon cluster reveals a precise, quietly ruthless evolution in modern espionage tradecraft: instead of treating each victim as a disposable data source, the operators systematically convert compromised IIS and SharePoint servers into active nodes in...