HomeSecurity'Ink Dragon' threat group targets IIS servers

'Ink Dragon' threat group targets IIS servers

A China-linked threat group known as 'Ink Dragon' is targeting common vulnerabilities in Internet Information Services (IIS) to create a global espionage network that is difficult to detect or disrupt, security firm Check Point. Also known by the aliases 'Earth Alux' (Trend Micro) and 'REF7707' (Elastic Security Labs), the group's activities date back to early 2023, when it targeted governments in Southeast Asia and South America.

See also: Chinese hackers exploit React2Shell vulnerability

Ink Dragon

Since then, its activity has expanded to target European countries. Ink Dragon may seem similar in its modus operandi to other Chinese threat groups involved in state-level surveillance, such as UNC6384, whose campaigns targeted European diplomats.

However, during a recent investigation into a European government office, Check Point said it discovered that the group has now shifted to what it calls "an unusually sophisticated plan" with long-term goals. Key to this is IIS, Microsoft's legacy web server platform, which still exists on many networks, especially in the public sector. This platform has two attractive features: it is widespread and often poorly configured and insecure.

The campaign begins when attackers compromise an IIS server, gain access to the internal network where they collect local credentials, study administrator sessions, using these and Microsoft Remote Desktop to move laterally without attracting attention. At this point, the group installs a custom IIS module that turns the server into an invisible 'silent' relay within the group's wider global infrastructure.

'These servers forward commands and data between different victims, creating a communication network that hides the true origin of the attack traffic,' Check Point researchers explain.

See also: CISA reports Chinese hackers using BRICKSTORM

'Ink Dragon' threat group targets IIS servers

The attack has two goals: to compromise government servers and plunder their networks for information, and secondly, to borrow them to relay offensive traffic to and from other compromised servers in a way that makes detecting the group's command and control (C2) much more difficult.

This tactic cleverly avoids the problem of relying on conventional C2 infrastructure that is vulnerable to collapse and disruption. Instead, compromised and trusted government servers become the infrastructure. In all cases, the same story repeats itself. A small problem encountered by the web becomes the first step. A series of quiet turns leads to domain-level control.

The environment is then reused as part of a larger network that feeds businesses across additional targets," Check Point said. As for traffic, the team hides the communication inside regular mailbox drafts, making it look like everyday communication.

Coincidentally, Check Point found that a second Chinese threat group, RudePanda, was simultaneously exploiting IIS vulnerabilities to compromise government servers. This meant that RudePanda 'ended up operating in the same [compromised] environments at the same time'. The findings highlight the issue of IIS misconfiguration. Beyond reporting the group's indicators of compromise (IoCs), Check Point offers no specific advice on how to address this.

See also: Chinese hackers APT31 target Russian IT companies

'Ink Dragon' threat group targets IIS servers

However, some actions are recommended: checking the modules running in IIS against a known good baseline, enabling advanced IIS logging, configuring IIS to reduce the likelihood of common view state vulnerabilities, and considering placing IIS servers behind a web application firewall (WAF).

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS