Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    ‘Everyone Is Doing It’: The Truth About AI in Hollywood

    August 4, 2026

    Did an AI Music App Just Snitch on the Song of the Summer?

    August 4, 2026

    Trump’s AI protectionism has come for robotics

    August 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • ‘Everyone Is Doing It’: The Truth About AI in Hollywood
    • Did an AI Music App Just Snitch on the Song of the Summer?
    • Trump’s AI protectionism has come for robotics
    • Turning Paper Charts Into Digital Medical Records
    • The ‘Guardrail Guy’ Went Viral for Posting About Flock Cameras. Then Someone Destroyed Them
    • The Download: reward hacking explained, and suspected Iranian cyberattacks
    • Simulation Apps Pinpoint Cause of Electronics Failures
    • AI Conquered Coding. Fast Food Is Next
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Webworm APT targets European government organizations with new backdoors
    Cybersecurity

    Webworm APT targets European government organizations with new backdoors

    kirklandc008@gmail.comBy kirklandc008@gmail.comMay 21, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Webworm APT targets European government organizations with new backdoors
    Share
    Facebook Twitter LinkedIn Pinterest Email

    ESET has released an analysis of the 2025 activity of Webworm, a China-aligned APT group tracked as Space Pirates and UAT-8302. Active since at least 2022, the group initially focused on targets in Asia, but has recently expanded its operations into Europe.

    ESET observed Webworm targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. The group also expanded its activity into South Africa, where researchers identified activity involving a local university.

    Discord messages expose infrastructure and targets

    By decrypting more than 400 Discord messages used for command-and-control (C&C) communication, ESET gained visibility into the group’s infrastructure and operations. The analysis revealed reconnaissance activity involving more than 50 unique targets.

    “Through our analysis, we were fortunate enough to recover commands executed from a server that gave a view into the group’s potential initial access techniques, using an open-source vulnerability scanner as well as identifying some of its focused targets,” said Eric Howard, ESET researcher who investigated the campaign.

    The recovered information led ESET to an attacker-operated GitHub repository used to host staged malware and supporting tools that could be downloaded onto victim systems.

    The repository contained artifacts including the SoftEther VPN application. Researchers identified an IP address in a SoftEther configuration file that matched infrastructure previously linked to Webworm.

    Forked WordPress repository (Source: ESET)

    New backdoors

    According to ESET, the group’s latest campaigns introduced two new backdoors: EchoCreep and GraphWorm.

    EchoCreep uses Discord for C&C communication, allowing attackers to upload files, send runtime reports, and receive commands.

    GraphWorm relies on Microsoft Graph API and OneDrive endpoints to retrieve tasks and upload victim information.

    The group expanded its use of proxy tools. Existing proxy capabilities were supplemented with custom tools including WormFrp, ChainWorm, SmuxProxy, and WormSocket. Based on the number and complexity of these tools, ESET believes Webworm may be building a larger hidden network by using compromised systems as proxy infrastructure.

    During the investigation, ESET discovered that Webworm had started using WormFrp to retrieve configurations from a compromised AWS S3 bucket.

    “It is apparent that through this S3 bucket, Webworm can leverage data exfiltration while an unsuspecting victim foots the bill for the service,” Howard said.

    Between December 2025 and January 2026, Webworm operators uploaded 20 new files to the service, two of which had been exfiltrated from a government organization in Spain.

    ESET noted that Webworm continues to stage files on GitHub and expects the group to maintain that approach in future campaigns.

    APT backdoors European government Organizations targets Webworm
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests

    July 31, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • ‘Everyone Is Doing It’: The Truth About AI in Hollywood
    • Did an AI Music App Just Snitch on the Song of the Summer?
    • Trump’s AI protectionism has come for robotics
    • Turning Paper Charts Into Digital Medical Records
    • The ‘Guardrail Guy’ Went Viral for Posting About Flock Cameras. Then Someone Destroyed Them

    ‘Everyone Is Doing It’: The Truth About AI in Hollywood

    August 4, 2026

    Did an AI Music App Just Snitch on the Song of the Summer?

    August 4, 2026

    Trump’s AI protectionism has come for robotics

    August 3, 2026

    Turning Paper Charts Into Digital Medical Records

    August 3, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.