216.73.217.22

New burrowing techniques

· Published 20/05/2026 17:45 · Modified 21/05/2026 17:12

Export JSON

Essential information

Published
20/05/2026 17:45
Modified
21/05/2026 17:12
Tags
2026-05-20 CVE-2017-7692 apt chainworm china-aligned cloud infrastructure discord c&c echocreep github staging graphworm mcrat microsoft graph api proxy tools smuxproxy trochilus vulnerability scanning wormfrp wormsocket
Related entities
1 vulnerabilities (cve), 1 intrusion sets (apt), 9 malware, 11 others

Description

Webworm is a group that has evolved its tactics since first being discovered in 2022, shifting focus from Asian targets to European governmental organizations. In 2025, the group deployed two new backdoors: , which uses Discord for command and control, and , which leverages . Researchers decrypted over 400 Discord messages revealing four victims and analyzed a compromised Amazon S3 bucket used for data exfiltration. The group stages tools in GitHub repositories and uses multiple custom proxy solutions including , , , and to create hidden networks. Webworm appears to exploit web vulnerabilities using tools like nuclei and dirsearch for initial access, targeting government entities and educational institutions across Europe and South Africa.

External references