ThreatCluster

GraphWorm Malware Exploits Microsoft OneDrive for Stealthy Cyber Espionage

First seen 20 May 2026, 12:09 UTC CybersecuritynewsGbhackers 90% similarity 73

Article Content

Browse articles
ThreatCluster

GraphWorm, a backdoor associated with the China-aligned APT group Webworm, has emerged as a significant threat in 2025, utilizing Microsoft OneDrive for command-and-control operations. This malware marks a shift in Webworm's tactics, now targeting European government entities instead of primarily Asian organizations. The use of cloud-based infrastructure allows for stealthier operations, complicating detection efforts. The evolution of this malware reflects the group's adaptation to enhance its cyber espionage capabilities. Specific details about the malware's functionality and the extent of its impact on affected organizations remain limited. Ongoing investigations are likely to reveal more about its operational scope and potential vulnerabilities. Security professionals are advised to monitor developments closely.

Key Points: • GraphWorm malware leverages Microsoft OneDrive for command-and-control operations. • The China-aligned APT group Webworm has shifted its focus to European government targets. • The malware represents an evolution in stealth techniques, complicating detection efforts.

ThreatCluster AI

Timeline

2025-01-01
Webworm's new tactics identified
Webworm began using Microsoft OneDrive for C2 operations, indicating a strategic shift in its cyber espionage approach.
Gbhackers
2025-05-01
GraphWorm backdoor reported
Security researchers documented the emergence of the GraphWorm backdoor as part of Webworm's evolving toolkit.
Cybersecuritynews

Community

Browse all →