Webworm is a China-aligned cyber-espionage threat actor active since at least 2017. It is tracked by multiple vendors as Webworm and has been linked to or assessed as overlapping with Space Pirates and UAT-8302; reporting also notes tradecraft commonalities with FishMonger and SixLittleMonkeys. The group has historically targeted government agencies and enterprises across Asia, including organizations in Russia, Georgia, and Mongolia, and later expanded operations into Europe and South Africa. Confirmed 2025 targeting includes government organizations in Belgium, Italy, Poland, Serbia, and Spain, as well as a university in South Africa. Reported sector targeting includes government, information technology services, aerospace, electric power, and academia. Webworm has used both legacy remote-access malware and newer custom tooling. Earlier activity featured customized variants of Trochilus, Gh0st RAT, and 9002 RAT, including multi-stage delivery chains that used DLL sideloading, staged shellcode execution, token theft, User Account Control bypasses, in-memory execution, and injection into svchost.exe. The actor modified malware communication protocols and configurations to evade detection and reused older or open-source malware families as a development base. More recent operations show a shift toward stealthier backdoors and proxy infrastructure. Webworm introduced EchoCreep, a Discord-based backdoor, and GraphWorm, a backdoor that uses Microsoft Graph API and OneDrive for command and control, tasking, and data transfer. Reporting also associates the group with backdoors and proxy tools such as GopherWhisper, WormFrp, ChainWorm, WormSocket, and SmuxProxy, as well as use of SoftEther VPN and other proxying utilities to route traffic through compromised systems and obscure operator origin. The breadth of this tooling suggests deliberate construction of covert relay and proxy networks. Observed tradecraft includes reconnaissance and vulnerability scanning against exposed services, use of publicly available cloud and collaboration platforms for command and control, malware staging through GitHub repositories, configuration retrieval from compromised cloud storage, and exfiltration of victim data to attacker-controlled cloud resources. Webworm has also been observed using process injection, persistence mechanisms tied to user logon and scheduled execution, privilege escalation through token theft and UAC bypass techniques, and post-compromise credential access tooling. The actor’s overall profile is consistent with long-term intelligence collection and covert access operations conducted in support of Chinese state-aligned espionage objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
52 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used legitimate platforms for command-and-control, deploying backdoors via Discord and the Microsoft Graph API.
Chinese state-linked group noted here for shared tradecraft and use of the Trochilus codebase alongside FishMonger and SixLittleMonkeys.
Chinese threat actor linked in the article through use of Trochilus and noted to share tradecraft commonalities with FishMonger and SixLittleMonkeys.
Cyber-espionage activity cluster active since at least 2017 that develops customized versions of older RATs and targets government agencies and enterprises in IT services, aerospace, and electric power sectors across Russia, Georgia, Mongolia, and other Asian countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.