Adversary Intelligence — 2026-05-25
China-Aligned Webworm APT Deploys EchoCreep and GraphWorm Backdoors Against EU Governments
BLUFFormal public attribution by any named EU member state remains unlikely by 30 November 2026, given the single-vendor evidentiary base and Webworm's reliance on commodity platforms that muddy the threshold for naming Beijing.
ESET Research on May 20 reported that Webworm targeted government entities in Belgium, Italy, Poland, Serbia, and Spain in 2025, and also compromised a local university in South Africa 12EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API" data-source="The Hacker News" data-url="https://thehackernews.com/2026/05/webworm-deploys-echocreep-and-graphworm.html" data-rt="secondary" data-otype="digital_news">3. The group's two new backdoors are EchoCreep, which uses Discord for C2, and GraphWorm, which uses Microsoft Graph API and OneDrive endpoints exclusively 123. ESET decrypted 433 Discord messages from EchoCreep's C2 channel, finding commands sent to more than 50 targets beginning March 21, 2024, and traced attribution to Webworm via a GitHub repository containing a SoftEther VPN configuration file matching a known Webworm IP 123. ESET has not identified the initial access vector, but observed the custom proxy tool WormFrp retrieving configurations from a compromised AWS S3 bucket that operators used to exfiltrate files from a Spanish government entity between December 2025 and January 2026 12.
AnalysisFormal EU attribution to China over the Webworm campaign is
unlikely by 30 November 2026. Moderate confidence rests on a single ESET vendor report with no corroboration from national intelligence services and an attribution chain anchored to one IP inside a SoftEther VPN configuration file. European governments have made formal attributions to China only when diplomatic preparations were underway and national intelligence independently corroborated vendor findings; neither precondition is currently observable. Reliance on commodity infrastructure, including Discord, Microsoft Graph, and Amazon S3, further blurs the evidentiary threshold governments must clear before accusing Beijing. Toolset overlap with multiple China-nexus clusters sharing open-source RATs also leaves open the possibility that this reflects contractor or affiliate activity rather than a unified state-directed operation. Attribution would open a coordinated EU diplomatic response and accelerate sanctions deliberations; absent that outcome, affected governments manage exposure through technical defenses alone.
6 sources
- ESET uncovers the expanded arsenal of China-aligned Webworm; European governments targeted - ESET / GlobeNewswire
- China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts - Dark Reading
- Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API - The Hacker News
- China Webworm Uses Discord Microsoft Graphs to Hack EU Governments - Dark Reading
- ESET uncovers the expanded arsenal of China-aligned Webworm; European governments targeted - ESET / GlobeNewswire
- Webworm: New burrowing techniques - ESET / WeLiveSecurity
View in full brief →