INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

China-Linked Webworm APT Evolves Tactics Expands to European Targets

| 2026-05-20 11:30 MEDIUM LOW STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
On May 20, 2026, the China-linked advanced persistent threat (APT) group Webworm expanded its victim list beyond Asia, targeting European governmental organizations. Analysis by ESET researchers in 2025 found that Webworm had already compromised government organizations in Belgium, Italy, Poland, Serbia, and Spain. The attack works by using two new backdoors: EchoCreep, which uses Discord to upload files and send runtime reports, and GraphWorm, which utilizes Microsoft Graph for command-and-control communication. As of the investigation, over 400 Discord messages were decrypted, revealing an attacker-operated server used for reconnaissance against more than 50 unique targets. The current status is unclear, but it appears that Webworm has successfully compromised several European organizations, with potential implications for sensitive information exfiltration and data theft.
Technical Mitigations AI-generated
• Patch SquirrelMail webmail service to prevent exploitation by Webworm. • Block or hunt for Discord messages and commands from unknown senders. • Monitor OneDrive endpoints exclusively, specifically for new jobs and uploaded victim information.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
BENELUX BENELUX governmentgovernment
Incident Timeline
‎2026/05/20
Webworm, a China-aligned advanced persistent threat (APT) group known for its cyber espionage campaigns, has expanded its victim list beyond Asia to European governmental organizations and compromised multiple targets in Europe.
victims 50 unique targets
Tactical Metrics
Metrics
victims
50
Unique Targets
Intelligence Sources
Infosecurity-Magazine 2026-05-20
Infosecurity-Magazine 2026-05-20