Webworm APT Expands Operations to Europe with New Backdoors

Webworm APT Expands Operations to Europe with New Backdoors

First seen 20 May 2026, 15:26 UTC Infosecurity-MagazineEsetWelivesecurityFeeds2.Feedburnersymantec-enterprise-blogs.security.com+6 85% similarity 75.5

Article Content

Browse articles
ThreatCluster

The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors, EchoCreep and GraphWorm, which utilize Discord and Microsoft Graph API for command-and-control communication. The group has also compromised a university in South Africa. Webworm's tactics have evolved, moving away from traditional RATs like Trochilus and 9002 RAT to more stealthy proxy tools and custom malware. The attackers have been observed using GitHub repositories to stage their malware, enhancing their evasion techniques. Victims have been notified, and some identified services have been taken down. The group is linked to previous operations and continues to adapt its methods.

Key Points: • Webworm has expanded its targeting from Asia to European government organizations. • New backdoors EchoCreep and GraphWorm utilize Discord and Microsoft Graph API for C2. • The group is known for staging malware in GitHub repositories to evade detection.

ThreatCluster AI

Timeline

2017-04-20
CVE-2017-7692 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-01-01
Webworm's European targeting begins
Webworm initiates cyber espionage campaigns against government organizations in Europe, marking a shift from its previous focus on Asia.
Welivesecurity
2025-05-19
ESET presents findings at ESET World
ESET researchers reveal details of Webworm's activities and new tactics during a presentation in Berlin.
Infosecurity-Magazine
2025-05-20
Webworm's activities reported
ESET publishes a comprehensive analysis of Webworm's 2025 campaigns, detailing its new tools and targets.
Welivesecurity

Community

Browse all →