China-Linked Webworm APT Evolves Tactics, Expands to European Targets
ID: 7e571c11-e22e-561d-a0cd-7562d15c739a
STIX ID: report--7e571c11-e22e-561d-a0cd-7562d15c739a
Feed Name: Infosecurity Magazine (News)
ESET researchers observed the China-aligned APT Webworm broaden its operations in 2025 to target European government organizations and a South African university, deploying new backdoors (Discord-based EchoCreep and Microsoft Graph-based GraphWorm), leveraging proxy toolsets (WormFrp, ChainWorm, SmuxProxy, WormSocket) for C2 and network extension, and exploiting an identified SquirrelMail vulnerability for initial access while using cloud endpoints (OneDrive, AWS S3) for job retrieval and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
