Skip to main content
Mallory
18 malware familiesExploits CVEs in the wild

Webworm

Also known asWebworm

Webworm is a China-aligned APT group active since at least 2017 according to Symantec reporting, and since at least 2022 according to ESET reporting. It is tracked as Space Pirates and UAT-8302, and reporting links it to SixLittleMonkeys and FishMonger; Symantec assessed Webworm and Space Pirates are likely the same entity. Webworm has targeted government agencies and enterprises, including organizations in the IT services, aerospace, and electric power sectors, with victims reported in Russia, Georgia, Mongolia, other Asian countries, and more recently Europe and South Africa. ESET observed 2025 targeting of government organizations in Belgium, Italy, Poland, Serbia, Spain, and activity involving a local university in South Africa. Webworm historically used customized versions of older RATs including Trochilus, Gh0st RAT, and 9002 RAT/McRat. Symantec described multi-stage droppers using legitimate executables and malicious DLL side-loading, staged shellcode execution, token theft from WINLOGON.EXE, CreateProcessAsUserW, UAC bypass components, file copying into C:\ProgramData\Logger, and in-memory execution of a modified Trochilus variant that injected into svchost.exe and supported command execution and file download. Symantec also reported modified Gh0st RAT and 9002 RAT droppers, including protocol changes to 9002 RAT to evade detection. More recent reporting shows a shift toward stealthier proxy and cloud-backed tooling. In 2025 Webworm introduced the backdoors EchoCreep and GraphWorm. EchoCreep is a Go-based backdoor that uses Discord for command and control and supports file upload, runtime reporting, and command execution. GraphWorm uses Microsoft Graph API and OneDrive for command and control, creates per-victim OneDrive folders and subfolders for tasking and results, persists via logon execution and Windows Run keys, and supports file transfer and shell command execution. Reporting also describes Webworm’s use of custom proxy tools WormFrp, ChainWorm, SmuxProxy, and WormSocket, alongside open-source tools such as frp, iox, and SoftEther VPN. ESET assessed the breadth and complexity of this proxy tooling suggests Webworm may be building a covert proxy network from compromised systems. Observed tradecraft includes abuse of public services such as Discord, Microsoft Graph, OneDrive, Slack, and a compromised AWS S3 bucket for command and control, configuration retrieval, and likely exfiltration. ESET decrypted more than 400 Discord messages tied to Webworm C2 and identified reconnaissance against more than 50 targets. Reporting states the group used dirsearch and nuclei for reconnaissance and vulnerability discovery, and a LegalHackers CVE-2017-7692 SquirrelMail post-authentication RCE script was found and may have been used against a Serbian webmail target. Webworm also used an attacker-operated GitHub repository masquerading as a WordPress fork to stage malware and tools. ESET reported exfiltration to the compromised S3 bucket, including files stolen from government entities in Spain and virtual machine snapshots tied to an Italian government entity. Additional reporting ties Webworm to infrastructure and tooling overlaps with ShadowPad/SNAPPYBEE-related tracking, and one source explicitly lists cross-tracker associations to Space Pirates and ShadowPad/SNAPPYBEE.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

14 of 15 tactics87 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1595×2
Active Scanning
T1595.002
Vulnerability Scanning
T1595.003
Wordlist Scanning
TA0042
Resource Development
4 techniques
T1583
Acquire Infrastructure
T1583.003
Virtual Private Server
T1583.004
Server
T1584
Compromise Infrastructure
T1584.006
Web Services
T1588
Obtain Capabilities
T1588.006
Vulnerabilities
T1608
Stage Capabilities
T1608.002
Upload Tool
TA0001
Initial Access
3 techniques
T1078
Valid Accounts
T1078.004
Cloud Accounts
T1133
External Remote Services
T1190×2
Exploit Public-Facing Application
TA0002
Execution
4 techniques
T1053×2
Scheduled Task/Job
T1053.005
Scheduled Task
T1059×2
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.003×4
Windows Command Shell
T1203
Exploitation for Client Execution
T1204
User Execution
T1204.002
Malicious File
TA0003
Persistence
6 techniques
T1053×2
Scheduled Task/Job
T1053.005
Scheduled Task
T1078
Valid Accounts
T1078.004
Cloud Accounts
T1112
Modify Registry
T1133
External Remote Services
T1543
Create or Modify System Process
T1543.003
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.001×2
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
7 techniques
T1053×2
Scheduled Task/Job
T1053.005
Scheduled Task
T1055
Process Injection
T1078
Valid Accounts
T1078.004
Cloud Accounts
T1134
Access Token Manipulation
T1543
Create or Modify System Process
T1543.003
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.001×2
Registry Run Keys / Startup Folder
T1548
Abuse Elevation Control Mechanism
T1548.002
Bypass User Account Control
TA0005
Stealth
8 techniques
T1027
Obfuscated Files or Information
T1027.013
Encrypted/Encoded File
T1036
Masquerading
T1055
Process Injection
T1070
Indicator Removal
T1070.004
File Deletion
T1070.006
Timestomp
T1078
Valid Accounts
T1078.004
Cloud Accounts
T1134
Access Token Manipulation
T1140
Deobfuscate/Decode Files or Information
T1620
Reflective Code Loading
TA0112
Defense Impairment
1 technique
T1112
Modify Registry
TA0006
Credential Access
1 technique
T1110
Brute Force
TA0007
Discovery
1 technique
T1082
System Information Discovery
TA0008
Lateral Movement
2 techniques
T1021
Remote Services
T1021.007
Cloud Services
T1550
Use Alternate Authentication Material
T1550.001
Application Access Token
TA0009
Collection
2 techniques
T1005
Data from Local System
T1074
Data Staged
T1074.001
Local Data Staging
T1074.002
Remote Data Staging
TA0011
Command and Control
8 techniques
T1071×5
Application Layer Protocol
T1071.001×3
Web Protocols
T1090×5
Proxy
T1090.001
Internal Proxy
T1090.002
External Proxy
T1090.003×2
Multi-hop Proxy
T1102
Web Service
T1102.002
Bidirectional Communication
T1105×5
Ingress Tool Transfer
T1132
Data Encoding
T1132.001
Standard Encoding
T1219
Remote Access Tools
T1572
Protocol Tunneling
T1573
Encrypted Channel
T1573.002
Asymmetric Cryptography
TA0010
Exfiltration
2 techniques
T1041×2
Exfiltration Over C2 Channel
T1567×2
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
IOCS

Observables

52 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

the hacker newsNews
May 20, 2026
Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API

China-aligned espionage activity targeting government agencies and enterprises, using custom backdoors, RATs, proxy tooling, GitHub-hosted staging infrastructure, and stealthy C2 via Discord and Microsoft Graph API.

Read more
cyber security newsNews
May 20, 2026
GraphWorm Malware Uses Microsoft OneDrive as Command-and-Control Infrastructure - Cyber Security News

China-aligned espionage-focused threat group using new custom backdoors and proxy tooling. It has shifted from earlier tools like McRat and Trochilus to stealthier malware such as GraphWorm and Choreerp, leveraging Microsoft OneDrive for command-and-control and targeting government and academic entities across Europe, Asia, and Africa.

Read more
eset welivesecurity blogNews
May 20, 2026
Webworm: New burrowing techniques

China-aligned espionage group active since at least 2022 that evolved from using RATs/backdoors toward stealthier proxy tooling, while in 2025 deploying new backdoors using Discord and Microsoft Graph API for command-and-control. It stages tools in GitHub, abuses a compromised Amazon S3 bucket, scans targets with dirsearch and nuclei, and targeted government entities and a university.

Read more
help net securityNews
May 20, 2026
Webworm APT targets European government organizations with new backdoors - Help Net Security

China-aligned espionage group active since at least 2022, targeting government organizations and a university, expanding from Asia into Europe and South Africa, and using Discord-, Microsoft Graph-, and OneDrive-based backdoors plus proxy infrastructure and GitHub staging.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping54

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal18

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables52

Domains, IPs, and hashes tied to this actor, refreshed continuously.