The Webworm campaign highlights how advanced threat actors are increasingly abusing legitimate cloud and collaboration platforms for command-and-control. According to the report, the China-aligned Webworm group deployed two new backdoors, EchoCreep and GraphWorm, using Discord and the Microsoft Graph API for C2 communication. This makes detection harder because malicious traffic can blend into services that many organizations already allow through their networks.

Webworm has reportedly targeted government agencies and enterprises across sectors such as IT services, aerospace, and electric power, with activity observed across Russia, Georgia, Mongolia, other Asian nations, and more recently European countries including Belgium, Italy, Serbia, and Poland. The group has also shifted from traditional RATs toward stealthier proxy tools, custom backdoors, GitHub staging repositories, and SoftEther VPN, which shows a clear focus on persistence, concealment, and flexible access. 

The capabilities of the new tools are concerning. EchoCreep supports command execution and file upload/download through Discord-based C2, while GraphWorm can create command sessions, execute processes, move files through Microsoft OneDrive, and terminate itself on operator command. Because naturally even malware now uses cloud productivity workflows better than some businesses do. 

Organizations should treat this as a reminder that blocking only “known bad” infrastructure is no longer enough. Security teams should monitor unusual use of Discord, Microsoft Graph API, OneDrive, GitHub, and VPN tools from servers or sensitive network segments. They should also watch for unexpected cmd.exe activity, suspicious proxy tools, abnormal file transfers, unauthorized cloud API calls, and lateral movement through chained internal hosts. 

The larger lesson is that trusted platforms can become attacker infrastructure. Enterprises need strong egress controls, DNS and web filtering, cloud API visibility, behavioral detection, least-privilege access, and network segmentation. When attackers hide inside common services, defenders need context, not just allow/block lists. A permitted cloud service should not automatically mean permitted behavior.


Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or C&C) communications. Webworm, first publicly documented by Broadcom-owned Symantec in September 2022, is assessed to be active since at least 2022, targeting government agencies

Source: Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API via The Hacker News — published 20 May 2026.