Hack.lu 2026

When Victims Become Infrastructure: Inside Ink Dragon’s Victim-Based Relay Network

Some of the most effective malicious traffic is the traffic no one thinks to question. In the Ink Dragon campaign, what appeared to be routine cross-border government connectivity was in fact the first visible layer of a hidden relay network.

In this talk, we present Ink Dragon, a China-nexus espionage cluster that has targeted government and telecommunications entities in Southeast Asia and is now expanding into Europe. Rather than deploying new infrastructure, the actor turned its victims into infrastructure - chaining compromised systems into a multi-hop relay network that routed commands and exfiltrated data across organizational and national boundaries while blending into trusted inter-government communication flows.

We detail how investigating a single compromised environment led us to uncover this relay network and map a campaign far larger than any individual victim could see. By pivoting from a compromised endpoint to the upstream relays feeding it and then tracing back downstream to other victims behind those same relays, we correlated activity across environments that appeared entirely unrelated, revealing dozens of previously unknown compromised systems while the operation was still active.

This investigation required fusing incident response, reverse engineering, and threat intelligence to connect what initially looked like isolated intrusions into a single coordinated operation. We provide technical deep dives into key components of the actor's arsenal, and show how analysis of these tools helped us link activity across victims and trace the relay network to its full extent. Ink Dragon is a case study in how modern espionage campaigns are designed to remain invisible at the single-organization level and what it takes to break that design.


The investigation begins with a single compromised government host. Incident response and forensic analysis revealed that this host was not an isolated intrusion: multiple servers within the same environment had already been compromised. Several of these systems communicated with upstream relays, while others hosted listeners that accepted inbound connections from downstream nodes. It became clear that this environment was not just a victim but an active component of a broader operational network.
From this single starting point, the research team pivoted upward. By following relay traffic to upstream nodes, dozens of additional compromised systems were identified across multiple organizations. Unlike traditional broad scanning or generic hunting techniques, these discoveries were made through precise correlation of observed relay behavior during incident response. Each newly identified victim reinforced the understanding that Ink Dragon leveraged victim infrastructure rather than deploying new assets, and highlighted how carefully the actor had designed the network to blend into routine traffic.
After mapping upstream relationships, the investigation pivoted back downward. Examining how relay nodes accepted and forwarded connections uncovered additional downstream victims that were not visible from the original host. This bidirectional pivoting - moving from victim to relay and from relay to downstream nodes- became a recurring investigative pattern throughout the operation, revealing the full scale of the espionage network while it was still active.
As the victim network footprint became clearer, attention shifted to the campaign’s tooling. Analysis uncovered additional command-and-control mechanisms, including abuse of the Microsoft Graph API to orchestrate activity via Office 365 accounts. This channel was decoupled from conventional network-based C2 infrastructure, yet pivoting through it enabled the identification of additional victims communicating via the same compromised accounts. These findings emphasized how modern espionage actors can operate across multiple technical layers while blending into expected enterprise and government traffic.
Each pivot contributed to a longitudinal view of the campaign: which systems were compromised, when they were incorporated into the relay network, how long they remained active, and how nodes were reused over time. This approach allowed the research team to track the campaign’s evolution, identify new victims with confidence, and in some cases take real-time mitigation steps that disrupted operations as they unfolded.
Throughout the talk, we emphasize the investigative process itself. Attendees will see how careful correlation, hypothesis testing, and iterative discovery were applied to move from a single compromised host to a multi-victim relay network. By presenting the campaign through the lens of the investigative journey rather than as a static end-state diagram, the audience will gain practical insight into the challenges and methodologies required to uncover victim-based relay networks.

Israel Gubi

Israel Gubi is a Senior Security Researcher at Check Point Research, where he focuses on threat hunting and reverse engineering of advanced persistent threat (APT) groups. Israel’s research has been presented at leading security conferences including Virus Bulletin, BlueHat, and AVA

Eli Smadja