National Cyber Warfare Foundation (NCWF)

Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API


0 user ratings
2026-05-20 13:29:09
milo
Blue Team (CND) , Attacks
Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or C&C) communications.

Webworm, first publicly documented by Broadcom-owned Symantec in September 2022, is assessed to be active since at least 2022, targeting government agencies



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/05/webworm-deploys-echocreep-and-graphworm.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)
Attacks



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.