China-aligned threat group Webworm has expanded its espionage toolkit with two custom backdoors, GraphWorm and EchoCreep, using trusted cloud and social platforms for command-and-control. Researchers said GraphWorm is a Go-based implant that abuses Microsoft OneDrive through the Microsoft Graph API, creating a separate workspace for each victim and using cloud folders for tasking, file transfer, shell command execution, configurable sleep intervals, and data exfiltration. EchoCreep was observed using Discord for C2, while the group also staged malware and supporting tools from a GitHub repository masquerading as a WordPress fork.
The activity reflects a broader shift by Webworm away from older RATs such as Trochilus and 9002 RAT toward stealthier proxy and tunneling infrastructure, including SoftEther VPN, WormFrp, ChainWorm, SmuxProxy, and WormSocket. Victims span government and enterprise organizations across Asia and Europe, including entities in Belgium, Italy, Serbia, Poland, and Spain, as well as a university in South Africa; researchers also linked a compromised Amazon S3 bucket to proxy configuration storage and exfiltrated data, including VM snapshots and government documents. Investigators observed the group using tools such as Nuclei and dirsearch, along with a script exploiting a known post-authentication RCE flaw in SquirrelMail, indicating active targeting of exposed web applications for initial access.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
On May 20, 2026, reporting based on ESET research disclosed that Webworm had upgraded its toolkit with GraphWorm and EchoCreep, expanded beyond Asia into Europe and South Africa, and used cloud services such as OneDrive and Discord for command and control.
On 2026-05-19, ESET Research published a GitHub repository of Webworm indicators of compromise, including malware hashes, filenames, detections, and infrastructure tied to tools such as EchoCreep, GraphWorm, WormFrp, ChainWorm, WormSocket, and SmuxProxy. The release also listed IP addresses associated with proxy servers, a web socket server, and a reverse shell endpoint observed in 2025.
Investigators identified a compromised Amazon S3 bucket used by Webworm to store proxy configuration data and exfiltrated information, including VM snapshots tied to an Italian government entity and documents from a Spanish government body.
Researchers found Webworm using a GitHub repository masquerading as a WordPress fork to host malware and operational tools for its campaign.
The group deployed proxy and tunneling tools including Wormsrp or WormFrp, ChainWorm, SmuxProxy, WormSocket, and SoftEther VPN to obscure attacker origin and route traffic through multiple hops.
Researchers observed the group using open-source tools such as Nuclei and dirsearch, along with a script for a known post-authentication remote code execution flaw in SquirrelMail, indicating active targeting of exposed web applications for initial access.
During its renewed 2025 operations, Webworm added two custom backdoors: GraphWorm, a Go-based implant using Microsoft OneDrive via the Graph API, and EchoCreep, which uses Discord for command and control.
Researchers reported renewed Webworm activity during 2025, including expanded targeting of organizations in Europe and a university in South Africa. Victims included government entities in Belgium, Italy, Serbia, Poland, and Spain.
Researchers observed Webworm using the custom EchoCreep backdoor with Discord-based command-and-control infrastructure. ESET said this activity dates back to March 21, 2024.
The China-aligned threat group Webworm has been active since at least 2017, initially focusing primarily on targets in Asia, including government and enterprise organizations in countries such as Russia, Georgia, and Mongolia.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 46 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
gist.github.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcewelivesecurity.com
Open sourcehelpnetsecurity.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.