China-Linked Ink Dragon Hacks Governments Using ShadowPad and FINALDRAFT Malware
Since July 2025, the threat actor known as Jewelbug has been concentrating more on European government targets while still attacking organizations in South America and Southeast Asia.
The cluster is being monitored by Check Point Research under the moniker Ink Dragon. The larger cybersecurity community also makes reference to it under the names Earth Alux, REF7707, and CL-STA-0049. It is estimated that the hacker gang with ties to China has been working since at least March 2023.
The cybersecurity firm stated in a technical analysis released on Tuesday that the actor's efforts combine strong software engineering, rigorous operational playbooks, and a readiness to reuse platform-native tools to blend into regular enterprise telemetry. Their incursions are both successful and covert b...



