ESET Research analyzed the recent activities of the pro-China APT group Webworm, a group that began using new backdoors for Command and Control (C&C) communications via Discord and the Microsoft Graph API in 2025, deciphering over 400 Discord messages. Among the tools used, EchoCreep and GraphWorm stand out. Webworm has also shifted focus to European government agencies and expanded operations into South Africa
Researchers of ESET, a global European leader in the cybersecurity market, analyzed the 2025 activities of Webworm, a pro-Chinese APT group initially active in Asia but recently focused on Europe. ESET observed attacks against government entities in Belgium, Italy, Poland, Serbia and Spain, as well as the compromise of a university in South Africa. Since last year, the group has been using backdoors that exploit Discord and the Microsoft Graph API for C&C communications. ESET researchers decrypted over 400 Discord messages and identified a server used for reconnaissance activities against more than 50 targets.
“Thanks to our analysis, we were fortunate to recover commands executed from a server that allowed us to understand the group's potential initial access techniques, using an open source vulnerability scanner, as well as identifying some of the main targets,” emphasizes Eric Howard, researcher at ESET, who discovered Webworm's latest activities.
ESET attributes the 2025 campaign to Webworm thanks to information obtained by decrypting Discord messages used by the EchoCreep backdoor. The traces led to an attackers' GitHub repository containing tools such as SoftEther VPN; An IP address already associated with Webworm was found in the configuration file.
The latest tools include two new backdoors: EchoCreep, based on Discord, and GraphWorm, which leverages Microsoft Graph. While continuing to use familiar proxy solutions, the group introduced custom proxy solutions such as WormFrp, ChainWorm, SmuxProxy, and WormSocket, likely to consolidate a larger hidden network by exploiting victims' systems.
Additionally, Webworm has started leveraging Discord and the Microsoft Graph API as C&C channels. The EchoCreep backdoor uses Discord to upload files, send runtime reports, and receive commands. GraphWorm uses the Microsoft Graph API for C&C communications; ESET researchers found that it exclusively uses OneDrive endpoints, specifically to capture new tasks and obtain victim information.
"During our investigation into the 2025 campaigns, we then discovered that Webworm had begun using its own custom proxy solution, WormFrp, to retrieve configurations from a compromised AWS S3 bucket, a public cloud storage solution available on Amazon Web Services, where S3 stands for Simple Storage Service. It is evident that through this S3 bucket, Webworm can exploit data exfiltration while an unsuspecting victim foots the bill for the service," concludes ESET's Howard. Between December 2025 and January 2026, operators uploaded 20 new files to the service, two of which had been exfiltrated from a government body in Spain.
The group continues to publish files on GitHub and ESET assumes that it will continue to do so in the future.
For more technical details on Webworm's latest efforts and arsenal, see ESET Research's latest blog post titled “Webworm: New burrowing techniques,” on WeLiveSecurity.com. Be sure to follow ESET Research on Twitter (today known as X), BlueSky, e Mastodon to stay updated on the latest news from ESET Research.






