Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API
ID: a481cc36-8403-5a35-93fb-27f92be89deb
STIX ID: report--a481cc36-8403-5a35-93fb-27f92be89deb
Feed Name: The Hacker News
Threat Score
Researchers observed activity in 2025 from the China-aligned APT "Webworm," which added two custom backdoors—EchoCreep (Discord-based C2) and GraphWorm (Microsoft Graph API-based C2)—and is increasingly using SoftEther VPN, custom proxy tools, and chaining to evade detection while targeting government and enterprise organizations across Asia, Europe, and Africa; the report also highlights a BadIIS malware-as-a-service offering linked to Chinese-speaking cybercriminals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
