Skip to content

GraphWorm Malware Abuses Microsoft OneDrive for Stealthy C2 Operations

Gbhackers Mayura Kathir May 20, 2026

A new activity from Webworm, a China-aligned advanced persistent threat (APT) group, revealing a significant evolution in its cyber espionage toolkit during 2025. The group, first publicly documented in 2022, has shifted its targeting from primarily Asian organizations to government entities across Europe, while adopting stealthier techniques and cloud-based command-and-control (C2) infrastructure. One of the […]

Extracted Entities

APT Groups (1)

Attack Types (1)

Industries (1)

Malware (1)

Platforms (1)