FinalDraft is a malware family tracked across 3 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed December 16, 2025; most recent activity May 5, 2026.
FinalDraft is a malware family linked to the Ink Dragon group, a Chinese state-backed threat actor. The campaigns describe FinalDraft as operating covertly within European government networks, enabling long-term access for espionage. Its significance stems from targeted government infrastructure and ongoing state-sponsored cyber intrusions in Europe.
In 2024, ESET identified a new China-aligned APT group named LongNosedGoblin, which targets governmental entities in Southeast Asia and Japan. The group employs a custom toolset, primarily using C#/.NET applications, to…
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
The Ink Dragon Group, linked to China, has infiltrated European government networks by exploiting misconfigured servers to establish relay nodes for cyber-espionage. Check Point reports that this campaign has affected…