logo

Webworm APT Expands Operations to Europe with New Backdoors

ID: 874f9645-ae73-595c-a14b-42fb48965251

STIX ID: report--874f9645-ae73-595c-a14b-42fb48965251

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-05-20

Date Updated: 2026-05-21

...
...

The report details Webworm, a China-aligned APT that expanded operations into Europe in 2025, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain (and a university in South Africa), deploying new backdoors EchoCreep (Discord-based) and GraphWorm (Microsoft Graph API-based) alongside modified RATs and proxy tools, staging malware in GitHub and using cloud services for exfiltration; it includes IOCs, decrypted Discord messages evidencing activity, and prioritized mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.