logo

GraphWorm Malware Abuses Microsoft OneDrive For C2 Operations

ID: 7eaeb6c3-fcf4-5076-9185-9e1322a3889d

STIX ID: report--7eaeb6c3-fcf4-5076-9185-9e1322a3889d

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Varshini

...
...

ESET researchers attribute a 2025 espionage campaign to the China-aligned APT group Webworm, which replaced older tools with two Go backdoors—GraphWorm (using Microsoft Graph/OneDrive for encrypted C2) and EchoCreep (Discord-based C2)—targeting government organizations across Europe and beyond; the report describes persistence, command capabilities, custom proxy infrastructure, victim countries, and provides SHA-1 indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.