Minacce · 131 giorni fa
Webworm si è spostato oltre un insieme di spionaggio regionale focalizzato sull’Asia. Il cambiamento che conta è la combinazione: un probabile foothold attraverso SquirrelMail dismesso, poi tooling basato su cloud e SaaS che fa sembrare l’intrusione normale traffico internet invece di una classica campagna di beaconing.
5 fonti che coprono questa storia
China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts
The advanced persistent threat group also relied on SOCKS proxies like SoftEther VPN, tunneling tools that act as a middleman between victim and attacker.
Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API
Webworm added EchoCreep and GraphWorm in 2025, using Discord and Microsoft Graph API C2 to expand stealth operations.
Webworm APT targets European government organizations with new backdoors - Help Net Security
ESET researchers uncover a Webworm APT threat campaign targeting Europe through trusted online services and tools.
China-Linked Webworm APT Evolves Tactics, Expands to European Targets
China-linked Webworm APT expands beyond Asia, targeting European government organizations and refining its cyber espionage tactics, according to ESET research
Webworm: New burrowing techniques
ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-05-21