Infosecurity-Magazine
Webworm APT Expands Operations to Europe with New Backdoors
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors, EchoCreep and GraphWorm, which utilize Discord and Microsoft Graph API for command-and-control communication. The group has also compromised a university in South Africa. Webworm's tactics have evolved, moving away from traditional RATs like Trochilus and 9002 RAT to more stealthy proxy tools and custom malware. The attackers have been observed using GitHub repositories to stage their malware, enhancing their evasion techniques. Victims have been notified, and some identified services have been taken down. The group is linked to previous operations and continues to adapt its methods.
Key Points: • Webworm has expanded its targeting from Asia to European government organizations. • New backdoors EchoCreep and GraphWorm utilize Discord and Microsoft Graph API for C2. • The group is known for staging malware in GitHub repositories to evade detection.