{"id":987,"date":"2026-05-20T13:52:10","date_gmt":"2026-05-20T13:52:10","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=987"},"modified":"2026-05-20T13:52:10","modified_gmt":"2026-05-20T13:52:10","slug":"webworm-deploys-echocreep-and-graphworm-backdoors-using-discord-and-ms-graph-api","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=987","title":{"rendered":"Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjt4cD52DtnzH5FM8ZMrW9KyPrD1ysrJURSmqalrw9f6siP8XxYqClsqV6ofHpM8ir7gBnmmvehj5HB1k0aSHdPmLtKKwtLLvjSi4ELa9eMq12maW7p56a2yBdl7xzdfv6893fvQxLIH0kKGYKnzYM_7-3XysWIGsSNiEYXBjmiWFqe0Pe8uq-TkWlQjjv4\/s1700-e365\/cyberattack-paki.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as <b>Webworm<\/b> in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or C&amp;C) communications.<\/p>\n<p>Webworm, first publicly documented by Broadcom-owned Symantec in September 2022, is assessed to be active since at least 2022, targeting government agencies and enterprises spanning IT services, aerospace, and electric power sectors in Russia, Georgia, Mongolia, and several other Asian nations.<\/p>\n<p>Attacks mounted by the group have leveraged remote access trojans (RATs) like Trochilus RAT, Gh0st RAT, and 9002 RAT (aka Hydraq and McRat). The threat actor is said to overlap with China-nexus clusters tracked as FishMonger (aka Aquatic Panda), <a href=\"https:\/\/www.welivesecurity.com\/2020\/05\/14\/mikroceen-spying-backdoor-high-profile-networks-central-asia\/\">SixLittleMonkeys<\/a>, and Space Pirates. SixLittleMonkeys is best known for deploying Gh0st RAT and a RAT called Mikroceen targeting entities in Central Asia, Russia, Belarus, and Mongolia.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abIn recent years, it has started moving toward both existing and custom proxy tools, which are more stealthy than full-fledged backdoors,\u00bb ESET researcher Eric Howard <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/webworm-new-burrowing-techniques\/\">said<\/a>. \u00abIn 2025, Webworm also added two new backdoors to its toolset: EchoCreep, which uses Discord for C&amp;C communication, and GraphWorm, which uses Microsoft Graph API for the same purpose.\u00bb<\/p>\n<p>Underlying these efforts is the use of a GitHub repository impersonating a WordPress fork (\u00abgithub[.]com\/anjsdgasdf\/WordPress\u00bb) as a staging ground for malware and tools like SoftEther VPN in an effort to blend in and fly under the radar. The reliance on SoftEther VPN is a <a href=\"https:\/\/thehackernews.com\/2023\/08\/china-linked-flax-typhoon-cyber.html\">tried-and-tested approach adopted by several Chinese hacking groups.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhiwVfQDc_kP-HsOpPT50FUgKEC4phePFJrLIjvygH6pnpTugpSdljuJbYv3JxpN5kdYx4X7VJlJBQ1-oDloLI6XkoPh2WrptVd_39HkuzQHvzeHqo8wQDhngv5swgmGgP30bhTlqBDwHPmqM0ljE1_LhdU4v40pxG8vuosm1-suck6gMGN3anvKiLbCuti\/s1700-e365\/time.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhiwVfQDc_kP-HsOpPT50FUgKEC4phePFJrLIjvygH6pnpTugpSdljuJbYv3JxpN5kdYx4X7VJlJBQ1-oDloLI6XkoPh2WrptVd_39HkuzQHvzeHqo8wQDhngv5swgmGgP30bhTlqBDwHPmqM0ljE1_LhdU4v40pxG8vuosm1-suck6gMGN3anvKiLbCuti\/s1700-e365\/time.png\" alt=\"\" border=\"0\" data-original-height=\"421\" data-original-width=\"1136\"\/><\/a><\/div>\n<p>Over the past two years, the adversary has been observed shifting away from traditional backdoors to (semi-)legitimate utilities such as SOCKS proxies, while also increasingly focusing on European countries, including governmental organizations in Belgium, Italy, Serbia, and Poland, and a local university in South Africa.<\/p>\n<p>The discovery of EchoCreep and GraphWorm marks an expansion of Webworm&#8217;s arsenal, even as Trochilus and 9002 RAT appear to have been abandoned by the threat actor. Other tools of note are iox and custom proxy solutions such as WormFrp, ChainWorm, SmuxProxy, and WormSocket. WormFrp has been found to retrieve configurations from a compromised Amazon S3 bucket.<\/p>\n<p>\u00abThese custom proxy tools are not only capable of encrypting communications, but also support chaining across multiple hosts both internally and externally to a network,\u00bb ESET said. \u00abWe believe that the operators use these tools in conjunction with SoftEther VPN to better cover their tracks and increase the stealth of their activities.\u00bb<\/p>\n<p>EchoCreep supports file upload\/download and command execution via \u00abcmd.exe\u00bb capabilities, while Graphworm is a more advanced backdoor that can spawn a new \u00abcmd.exe\u00bb session, execute a newly created process, upload and download files to and from Microsoft OneDrive, and stop its own execution after receiving a signal from the operators.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh-rTXnA1Y9juitOOYVDzBuX44_jMK5RmaMY-UfcLng2EWv6V0RoB1R1owhC7PNu_XGa9woDcq4vnL_-UvR_5A8u7jRvW-FGmjkOiHpGNoG5Ibk5YqOOGNT9LHocAG8Jna_t4R7HkyCxsjibIMm5jfsVNBzrO9pCsrtHv7C2GgvLT8z0esoZYMTE2o-7den\/s1700-e365\/badiis.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh-rTXnA1Y9juitOOYVDzBuX44_jMK5RmaMY-UfcLng2EWv6V0RoB1R1owhC7PNu_XGa9woDcq4vnL_-UvR_5A8u7jRvW-FGmjkOiHpGNoG5Ibk5YqOOGNT9LHocAG8Jna_t4R7HkyCxsjibIMm5jfsVNBzrO9pCsrtHv7C2GgvLT8z0esoZYMTE2o-7den\/s1700-e365\/badiis.jpg\" alt=\"\" border=\"0\" data-original-height=\"635\" data-original-width=\"1000\"\/><\/a><\/div>\n<p>An analysis of the Discord channel leveraged by EchoCreep as C2 shows that the earliest commands were sent as far back as March 21, 2024. In all, 433 Discord messages have been sent via the C2 server.<\/p>\n<p>Exactly how these backdoors are delivered, and the initial access pathway used by Webworm, is presently unknown. However, it has emerged that the attacker utilizes open-source utilities like dirsearch and nuclei to brute-force victim web server files and directories, and search for vulnerabilities within.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The disclosure comes as Cisco Talos <a href=\"https:\/\/blog.talosintelligence.com\/from-pdb-strings-to-maas-tracking-a-commodity-badiis-ecosystem\/\">shed light<\/a> on a BadIIS variant that&#8217;s likely sold or shared among multiple Chinese-speaking cybercrime groups under a malware-as-a-service (MaaS) model designed for continuous monetization. The offering is believed to have been under development since at least September 30, 2021.<\/p>\n<p>The same malware author, who operates under the alias \u00ablwxat,\u00bb has also made available a set of supplementary tools, including service-based installers, droppers, and persistence mechanisms that automate deployment, ensure survivability across IIS server restarts, and sidestep detection.<\/p>\n<p>The service offers a dedicated builder tool that \u00aballows threat actors to generate configuration files, customize payloads, and inject parameters into BadIIS binaries &#8211; enabling capabilities including traffic redirection to illicit sites, reverse proxying for search engine crawler manipulation, content hijacking, and backlink injection for malicious search engine optimization (SEO) fraud,\u00bb Talos researcher Joey Chen said.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or&hellip;<\/p>\n","protected":false},"author":1,"featured_media":988,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[14,104,297,1749,1747,1361,1748,1746],"class_list":["post-987","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-api","tag-backdoors","tag-deploys","tag-discord","tag-echocreep","tag-graph","tag-graphworm","tag-webworm"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/987","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=987"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/987\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/988"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=987"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=987"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=987"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}