logo

GraphWorm Malware Abuses Microsoft OneDrive for Stealthy C2 Operations

ID: 3cf59657-0645-5c1e-ac32-d6d66b8540ee

STIX ID: report--3cf59657-0645-5c1e-ac32-d6d66b8540ee

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Mayura Kathir

...
...

This report describes Webworm, a China-aligned APT, evolving in 2025 to use stealthy, cloud-based C2 including a OneDrive/Graph API backdoor (GraphWorm) and a Discord-based backdoor (EchoCreep), supported by custom proxy tools and abused cloud hosting/storage; the campaign targeted multiple European governments and resulted in exfiltration of sensitive data, with detailed IOCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.