GraphWorm Malware Abuses Microsoft OneDrive for Stealthy C2 Operations
ID: 3cf59657-0645-5c1e-ac32-d6d66b8540ee
STIX ID: report--3cf59657-0645-5c1e-ac32-d6d66b8540ee
Feed Name: GBHackers
Threat Score
This report describes Webworm, a China-aligned APT, evolving in 2025 to use stealthy, cloud-based C2 including a OneDrive/Graph API backdoor (GraphWorm) and a Discord-based backdoor (EchoCreep), supported by custom proxy tools and abused cloud hosting/storage; the campaign targeted multiple European governments and resulted in exfiltration of sensitive data, with detailed IOCs provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
