Infosecurity-Magazine
Webworm APT Expands Operations to Europe with New Backdoors
Article Content
The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors, EchoCreep and GraphWorm, which utilize Discord and Microsoft Graph API for command-and-control communication. The group has also compromised a university in South Africa. Webworm's tactics have evolved, moving away from traditional RATs like Trochilus and 9002 RAT to more stealthy proxy tools and custom malware. The attackers have been observed using GitHub repositories to stage their malware, enhancing their evasion techniques. Victims have been notified, and some identified services have been taken down. The group is linked to previous operations and continues to adapt its methods.
Key Points: • Webworm has expanded its targeting from Asia to European government organizations. • New backdoors EchoCreep and GraphWorm utilize Discord and Microsoft Graph API for C2. • The group is known for staging malware in GitHub repositories to evade detection.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.