Wednesday, 20 May 2026

Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API

iT4iNT SERVER Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or C&C) communications.

Webworm, first publicly documented by Broadcom-owned Symantec in September 2022, is assessed to be active since at least 2022, targeting government agencies VDS VPS Cloud


http://dlvr.it/TSdZy2

No comments:

Post a Comment

Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

iT4iNT SERVER A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email cre...