logo

Webworm APT targets European government organizations with new backdoors

ID: 9ab15b82-b5f9-5a17-8247-b3853190d875

STIX ID: report--9ab15b82-b5f9-5a17-8247-b3853190d875

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Anamarija Pogorelec

...
...

ESET reports that Webworm (Space Pirates/UAT-8302) expanded operations in 2025, targeting government entities in multiple European countries and a South African university. Researchers decrypted Discord C2 messages exposing infrastructure and reconnaissance against 50+ targets, found a GitHub repository and SoftEther configuration linking attacker infrastructure, and observed new backdoors (EchoCreep using Discord C2 and GraphWorm using Microsoft Graph/OneDrive), plus custom proxy tooling and exfiltration of files to an AWS S3 bucket and GitHub staging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.