INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
China-Linked Webworm APT Evolves Tactics Expands to European Targets
| 2026-05-20 11:30 STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
On May 20, 2026, the China-linked advanced persistent threat (APT) group Webworm expanded its victim list beyond Asia, targeting European governmental organizations. Analysis by ESET researchers in 2025 found that Webworm had already compromised government organizations in Belgium, Italy, Poland, Serbia, and Spain. The attack works by using two new backdoors: EchoCreep, which uses Discord to upload files and send runtime reports, and GraphWorm, which utilizes Microsoft Graph for command-and-control communication. As of the investigation, over 400 Discord messages were decrypted, revealing an attacker-operated server used for reconnaissance against more than 50 unique targets. The current status is unclear, but it appears that Webworm has successfully compromised several European organizations, with potential implications for sensitive information exfiltration and data theft.
Technical Mitigations AI-generated
• Patch SquirrelMail webmail service to prevent exploitation by Webworm.
• Block or hunt for Discord messages and commands from unknown senders.
• Monitor OneDrive endpoints exclusively, specifically for new jobs and uploaded victim information.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Incident Timeline
Tactical Metrics
Intelligence Sources
Infosecurity-Magazine
2026-05-20
China-Linked Webworm APT Evolves Tactics, Expands to European Targets
Infosecurity-Magazine
Infosecurity-Magazine
2026-05-20
China-Linked Webworm APT Evolves Tactics, Expands to European Targets
Infosecurity-Magazine