Webworm Leaves Asia, Targets Europe Through Legacy Webmail

Webworm has moved beyond a regional Asia-focused espionage set. The change that matters is the mix: a likely foothold through discontinued SquirrelMail, then cloud and SaaS-backed tooling that makes the intrusion look like normal internet traffic instead of a classic beaconing campaign. ESET says Webworm activity in 2025 hit government organizations in Belgium, Italy, Poland, Serbia, and Spain, plus a university in South Africa. It also identified two new backdoors, EchoCreep on Discord and GraphWorm through Microsoft Graph and OneDrive, which fits a low-footprint operator that can shift storage and command traffic into victim-linked cloud services. The forward risk is geographic and detection-related. European government networks and universities exposed through old webmail services can now be reached by an actor that does not need heavy infrastructure, so perimeter hunting alone will miss parts of the intrusion and the cloud footprint it leaves behind.

Part of the PlainSec briefing for 2026-05-21

Sources