logo

Webworm: New burrowing techniques

ID: d9405eea-137f-51dd-8306-5776ddafbdb2

STIX ID: report--d9405eea-137f-51dd-8306-5776ddafbdb2

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
88/100

Date Published: 2026-05-20

Date Updated: 2026-05-21

...
...

**ESET analyzed the 2025 activity of Webworm, a China-aligned APT, documenting a shift from traditional RATs to stealthier proxy tooling and two new backdoors that use Discord (EchoCreep) and the Microsoft Graph API/OneDrive (GraphWorm) for C2; the report details targeted campaigns against European government entities and other victims, staging on public GitHub and a compromised Amazon S3 bucket, provides IoCs (file hashes, IPs, domains), and maps observed behaviors to MITRE ATT&CK techniques.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.