FINALDRAFT Backdoor - Remove Spyware & Malware with SpyHunter - EnigmaSoft Ltd
Summary
This article tracks a China-aligned threat group that uses FINALDRAFT and related tools to compromise organizations across Europe, Asia, Africa, and other regions. The attackers exploit vulnerable web applications, SharePoint flaws, weak ASP.NET machine keys, and stolen credentials to gain deep access and move laterally. They also turn compromised servers into relay nodes, which helps them hide command-and-control traffic and maintain long-term persistence. Defenders need to focus on disrupting the whole relay chain, not just isolated infected systems.
Classifications
industries
Entertainment
applications
Customer Service & Support
AskAI Classifications
Labels
Cybersecurity Software
Anti-Malware Software
SaaS Security
Linked Companies
EnigmaSoft
$1M to $5M