Threats · 116 days ago
Webworm has moved beyond a regional Asia-focused espionage set. The change that matters is the mix: a likely foothold through discontinued SquirrelMail, then cloud and SaaS-backed tooling that makes the intrusion look like normal internet traffic instead of a classic beaconing campaign.
ESET says Webworm activity in 2025 hit government organizations in Belgium, Italy, Poland, Serbia, and Spain, plus a university in South Africa. It also identified two new backdoors, EchoCreep on Discord and GraphWorm through Microsoft Graph and OneDrive, which fits a low-footprint operator that can shift storage and command traffic into victim-linked cloud services.
The forward risk is geographic and detection-related. European government networks and universities exposed through old webmail services can now be reached by an actor that does not need heavy infrastructure, so perimeter hunting alone will miss parts of the intrusion and the cloud footprint it leaves behind.
5 sources covering this story
China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts
The advanced persistent threat group also relied on SOCKS proxies like SoftEther VPN, tunneling tools that act as a middleman between victim and attacker.
Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API
Webworm added EchoCreep and GraphWorm in 2025, using Discord and Microsoft Graph API C2 to expand stealth operations.
Webworm APT targets European government organizations with new backdoors - Help Net Security
ESET researchers uncover a Webworm APT threat campaign targeting Europe through trusted online services and tools.
China-Linked Webworm APT Evolves Tactics, Expands to European Targets
China-linked Webworm APT expands beyond Asia, targeting European government organizations and refining its cyber espionage tactics, according to ESET research
Webworm: New burrowing techniques
ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal.
Part of the PlainSec briefing for 2026-05-21