AI Security 3mo ago Updated 21m ago 85

China's Webworm Uses Discord, Microsoft Graphs to Hack EU Governments

ESET identified a China-backed APT group called Webworm targeting European government organizations in Belgium, Italy, Serbia, Spain, and Poland, as well as entities in South Africa. The threat actor has shifted from using well-known malware families like McRat and Trochilus to stealthier proxy-based command-and-control mechanisms starting in 2024. In 2025, Webworm introduced two new backdoors: EchoCreep, which uses Discord for C2, and GraphWorm, which leverages the Microsoft Graph API. ESET ana

85
Hot
90
Quality
80
Impact

Analysis

TL;DR

  • ESET identified a China-backed APT group called Webworm targeting European government organizations in Belgium, Italy, Serbia, Spain, and Poland, as well as entities in South Africa.
  • The threat actor has shifted from using well-known malware families like McRat and Trochilus to stealthier proxy-based command-and-control mechanisms starting in 2024.
  • In 2025, Webworm introduced two new backdoors: EchoCreep, which uses Discord for C2, and GraphWorm, which leverages the Microsoft Graph API.
  • ESET analyzed 400 decrypted Discord messages to attribute activity to Webworm, linking it to a specific GitHub repository and known IP addresses.
  • The group utilizes custom proxy tools such as WormFrp, SmuxProxy, and WormSocket alongside SoftEther VPN to create a hidden network infrastructure on Vultr and IT7 Networks cloud servers.

Why It Matters

This report highlights a significant evolution in advanced persistent threat (APT) tactics where attackers increasingly abuse trusted, mainstream consumer platforms like Discord and Microsoft Graph for command and control, thereby bypassing traditional network traffic analysis that looks for standard C2 patterns. For security practitioners, this underscores the critical need to monitor internal communications for anomalous data exfiltration to non-standard endpoints and to restrict outbound traffic to unauthorized cloud or chat services. It also signals that European governmental organizations are facing targeted espionage campaigns designed to establish deep pivot points for long-term intelligence gathering.

Key Data

  • Target Locations: Governmental organizations in Belgium, Italy, Serbia, Spain, Poland, and South Africa.
  • Research Period: The study predominantly covers activity between early 2024 and early 2025, with specific focus on 2025 techniques.
  • Data Sample: ESET’s attribution relied on the analysis of 400 Discord messages.
  • Infrastructure: Proxy tools and VPN services are hosted on cloud servers controlled by Vultr and IT7 Networks.
  • Attribution Link: Decrypted Discord messages led to a GitHub repository containing an IP address matching a known Webworm identifier.

Technical Details

  • Evolution of C2 Mechanisms: Webworm initially used malware families McRat and Trochilus. In 2024, it pivoted to using legitimate or semi-legitimate networking tools, such as SOCKS proxies via SoftEther VPN, to act as middlemen for communications, which are harder to detect than traditional backdoors due to lack of static signatures.
  • New Backdoors (2025): The actor introduced EchoCreep, a backdoor that uses Discord servers for uploading files, sending runtime reports, and receiving commands via crafted HTTP requests through Discord's API. Each victim is assigned a different Discord server.
  • GraphWorm Implementation: Webworm deployed GraphWorm, which utilizes Microsoft Graph API and OneDrive endpoints to retrieve new jobs and upload victim information. Distinct OneDrive directories are used for each victim to isolate data.
  • Proxy and Chaining Tools: To maintain stealth and chain hosts internally and externally, the group uses port forwarding and the proxy tool iox, alongside custom tools named ChainWorm, SmuxProxy, WormFrp, and WormSocket.
  • Configuration Retrieval: The actor uses the custom proxy solution WormFrp to retrieve configurations from compromised Amazon S3 buckets, demonstrating a multi-stage configuration management process.

Industry Insight

  • Trust Boundary Erosion: The use of Discord and Microsoft Graph for C2 indicates that defenders can no longer treat major SaaS platforms as inherently safe channels for data integrity. Security teams must implement egress filtering and strict application allowlisting to prevent malware from tunneling through legitimate business applications.
  • Stealth via Complexity: The development of custom proxy tools (e.g., WormFrp, SmuxProxy) suggests APT groups are investing in complex infrastructure to create "hidden networks" by tricking victims into running proxies. This implies that threat intelligence should track not just malicious binaries, but also the unusual networking dependencies they install.
  • Preventive Patching Priority: Since Webworm relies on open-source vulnerability scanners to find initial entry points, maintaining rigorous patch management and minimizing the attack surface of web-facing assets remains the most effective primary defense against this specific TTP.

zations targeted by Webworm?
A: Organizations should keep systems patched and limit asset exposure to reduce the chance of initial compromise via vulnerability scanning. Additionally, they should monitor communication activities from non-standard processes to endpoints like Discord, Microsoft Graph, or S3, and investigate any data transfers to these locations that do not align with standard workflows.

Disclaimer: The above content is generated by AI and is for reference only.

Frequently Asked Questions

How did ESET attribute the new backdoors to the Webworm APT group?

ESET attributed the activity by decrypting Discord messages used by the EchoCreep backdoor, which led to the discovery of a GitHub repository. This repository contained an IP address that matched a known Webworm IP, linking the new malware to the established threat actor.

✉️ Free Newsletter

Get the Best AI Signals Daily

Join 1,000+ founders, investors, and builders. Top AI stories, deep analysis, and what to watch — delivered every morning.

No spam. Unsubscribe anytime.