Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Webworm Uses Discord and MS Graph for New Backdoors

Webworm Uses Discord and MS Graph for New Backdoors

Posted on May 20, 2026 By CWS

Recent reports have unveiled fresh cyber activities from the China-aligned group known as Webworm. The threat actor has been active in 2025, deploying custom backdoors that exploit Discord and Microsoft Graph API for command-and-control communications. These developments highlight the evolving tactics of Webworm as it targets entities across Russia, Georgia, Mongolia, and other Asian countries.

Webworm’s Evolving Tactics and Targets

Originally documented by Symantec in September 2022, Webworm has been engaged in cyber espionage since at least 2022. Its targets include government bodies and businesses in sectors like IT services, aerospace, and electric power. The group’s operations reveal overlaps with other China-based clusters such as FishMonger, SixLittleMonkeys, and Space Pirates. Notably, SixLittleMonkeys is known for deploying Gh0st RAT, focusing on countries like Central Asia, Russia, and Mongolia.

ESET researcher Eric Howard notes that Webworm has shifted towards more discreet proxy tools, stepping away from traditional backdoors. This shift is evidenced by the introduction of EchoCreep and GraphWorm in 2025, which utilize Discord and Microsoft Graph API, respectively, for communications.

Undercover Tactics and Tools

Webworm’s strategy involves using a GitHub repository masquerading as a WordPress project to stage malware and tools like SoftEther VPN, enhancing their stealth. SoftEther VPN is a common choice among Chinese hacking groups for bypassing detection. Over the past two years, Webworm has moved towards semi-legitimate utilities such as SOCKS proxies, expanding their focus to European countries like Belgium, Italy, Serbia, and Poland.

The recent addition of EchoCreep and GraphWorm marks a significant expansion in Webworm’s arsenal, even though traditional tools like Trochilus and 9002 RAT have been abandoned. Other notable tools include custom proxy solutions such as WormFrp and SmuxProxy, with WormFrp retrieving configurations from a compromised Amazon S3 bucket.

Capabilities and Deliveries

EchoCreep is capable of file transfers and command execution, while GraphWorm offers advanced features like process execution and file management with Microsoft OneDrive. The exact methods used by Webworm to deploy these backdoors remain unclear, but the use of open-source utilities like dirsearch and nuclei indicates efforts to brute-force web server files and identify vulnerabilities.

This disclosure comes as Cisco Talos highlights a BadIIS variant, potentially shared among Chinese-speaking cybercriminals under a malware-as-a-service model since 2021. The malware author, known as “lwxat,” has provided additional tools to ensure persistence and evade detection.

As Webworm continues to enhance its cyber arsenal, the importance of vigilance and robust cybersecurity measures remains crucial for potential targets worldwide.

The Hacker News Tags:Backdoors, China-aligned threat, cyber attacks, Cybersecurity, Discord, EchoCreep, ESET, GraphWorm, Microsoft Graph API, Webworm

Post navigation

Previous Post: Go Module Typo Exposes DNS Backdoor Hack
Next Post: 1Password and OpenAI Enhance Security for AI Coding Tools

Related Posts

Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability The Hacker News
BraZetsu Malware Transforms Windows Systems into Crime Network BraZetsu Malware Transforms Windows Systems into Crime Network The Hacker News
LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets The Hacker News
GigaWiper Malware: A New Threat to Windows Systems GigaWiper Malware: A New Threat to Windows Systems The Hacker News
Critical LiteLLM Vulnerability Leads to Exploits Critical LiteLLM Vulnerability Leads to Exploits The Hacker News
Key Insights from Gartner’s Guardian Agents Guide Key Insights from Gartner’s Guardian Agents Guide The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark