← All reports

The Webworm APT group has developed new backdoors, EchoCreep and GraphWorm, that use Discord and Microsoft Graph API for command and control.

CybersecurityConflictTechnologyMay 24, 2026score 0.292 posts · 1 replies across 1 instances
The thread discusses the evolution of the Webworm APT group, which has developed new backdoors (EchoCreep and GraphWorm) using Discord and Microsoft Graph API for command and control. This highlights growing cybersecurity threats and the exploitation of cloud services by malicious actors.

Claims

The Webworm APT group has developed new backdoors, EchoCreep and GraphWorm, that use Discord and Microsoft Graph API for command and control.
Parent: CybersecurityEntity: Webworm APT groupImpact: negativeDate: May 24, 2026Target: The effectiveness of cybersecurity measures against evolving APT threats

Source posts

@[email protected]
Webworm evolve: i backdoor EchoCreep e GraphWorm trasformano Discord e Microsoft Graph in canali C2 - (in)sicurezza digitale https://insicurezzadigitale.com/webworm-evolve-i-backdoor-echocreep-e-graphworm-trasformano-discord-e-microsoft-graph-in-canali-c2/ > Webworm, APT di allineamento cinese attivo dal 2022, ha aggiornato il suo arsenale con due nuovi backdoor: EchoCreep, che usa Discord come canale C2, e GraphWorm, che sfrutta Microsoft Graph API e OneDrive per comunicare con gli
0 boosts · 0 favs · 1 replies · May 24, 2026
@[email protected]
Webworm evolve: i backdoor EchoCreep e GraphWorm trasformano Discord e Microsoft Graph in canali C2 - (in)sicurezza digitale insicurezzadigitale.com/webworm-evol... > Webworm, APT di allineamento cinese attivo dal 2022, ha aggiornato il suo arsenale con due nuovi backdoor:
0 boosts · 0 favs · 0 replies · May 24, 2026