{"id":250433,"date":"2026-05-20T08:51:00","date_gmt":"2026-05-20T12:51:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/05\/20\/webworm-deploys-echocreep-and-graphworm-backdoors-using-discord-and-ms-graph-api\/"},"modified":"2026-05-20T10:45:08","modified_gmt":"2026-05-20T14:45:08","slug":"webworm-deploys-echocreep-and-graphworm-backdoors-using-discord-and-ms-graph-api","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/05\/20\/webworm-deploys-echocreep-and-graphworm-backdoors-using-discord-and-ms-graph-api\/","title":{"rendered":"Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/webworm-deploys-echocreep-and-graphworm.html\">Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/webworm-deploys-echocreep-and-graphworm.html\">https:\/\/thehackernews.com\/2026\/05\/webworm-deploys-echocreep-and-graphworm.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-20 08:51:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p>Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or C&#038;C) communications.<\/p>\n<p>Webworm, first publicly documented by Broadcom-owned Symantec in September 2022, is assessed to be active since at least 2022, targeting government agencies and enterprises spanning IT services, aerospace, and electric power sectors in Russia, Georgia, Mongolia, and several other Asian nations.<\/p>\n<p>Attacks mounted by the group have leveraged remote access trojans (RATs) like Trochilus RAT, Gh0st RAT, and 9002 RAT (aka Hydraq and McRat). The threat actor is said to overlap with China-nexus clusters tracked as FishMonger (aka Aquatic Panda), SixLittleMonkeys, and Space Pirates. SixLittleMonkeys is best known for deploying Gh0st RAT and a RAT called Mikroceen targeting entities in Central Asia, Russia, Belarus, and Mongolia.<\/p>\n<p>&#8220;In recent years, it has started moving toward both existing and custom proxy tools, which are more stealthy than full-fledged backdoors,&#8221; ESET researcher Eric Howard said. &#8220;In 2025, Webworm also added two new backdoors to its toolset: EchoCreep, which uses Discord for C&#038;C communication, and GraphWorm, which uses Microsoft Graph API for the same purpose.&#8221;<\/p>\n<p>Underlying these efforts is the use of a GitHub repository impersonating a WordPress fork (&#8220;github[.]com\/anjsdgasdf\/WordPress&#8221;) as a staging ground for malware and tools like SoftEther VPN in an effort to blend in and fly under the radar. The reliance on SoftEther VPN is a tried-and-tested approach adopted by several Chinese hacking groups.<\/p>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"421\" data-original-width=\"1136\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhiwVfQDc_kP-HsOpPT50FUgKEC4phePFJrLIjvygH6pnpTugpSdljuJbYv3JxpN5kdYx4X7VJlJBQ1-oDloLI6XkoPh2WrptVd_39HkuzQHvzeHqo8wQDhngv5swgmGgP30bhTlqBDwHPmqM0ljE1_LhdU4v40pxG8vuosm1-suck6gMGN3anvKiLbCuti\/s1600\/time.png\"\/><\/p>\n<p>Over the past two years, the adversary has been observed shifting away from traditional backdoors to (semi-)legitimate utilities such as SOCKS proxies, while also increasingly focusing on European countries, including governmental organizations in Belgium, Italy, Serbia, Poland, and Spain, and a local university in South&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/webworm-deploys-echocreep-and-graphworm.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API https:\/\/thehackernews.com\/2026\/05\/webworm-deploys-echocreep-and-graphworm.html Publish Date:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":250434,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjt4cD52DtnzH5FM8ZMrW9KyPrD1ysrJURSmqalrw9f6siP8XxYqClsqV6ofHpM8ir7gBnmmvehj5HB1k0aSHdPmLtKKwtLLvjSi4ELa9eMq12maW7p56a2yBdl7xzdfv6893fvQxLIH0kKGYKnzYM_7-3XysWIGsSNiEYXBjmiWFqe0Pe8uq-TkWlQjjv4\/s1600\/cyberattack-paki.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,32,34],"class_list":["post-250433","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-malware","tag-threat-actor"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/250433"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=250433"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/250433\/revisions"}],"predecessor-version":[{"id":250436,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/250433\/revisions\/250436"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/250434"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=250433"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=250433"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=250433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}