logo

Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API

ID: a481cc36-8403-5a35-93fb-27f92be89deb

STIX ID: report--a481cc36-8403-5a35-93fb-27f92be89deb

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: [email protected] (The Hacker News)

...
...

Researchers observed activity in 2025 from the China-aligned APT "Webworm," which added two custom backdoors—EchoCreep (Discord-based C2) and GraphWorm (Microsoft Graph API-based C2)—and is increasingly using SoftEther VPN, custom proxy tools, and chaining to evade detection while targeting government and enterprise organizations across Asia, Europe, and Africa; the report also highlights a BadIIS malware-as-a-service offering linked to Chinese-speaking cybercriminals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.