China-aligned hacking group Webworm used new custom backdoors in 2025 that relied on Discord and Microsoft Graph API for command and control, according to a technical analysis from ESET. The report said the group has been active since at least 2022 and had expanded its toolset to include EchoCreep and GraphWorm.
KEY FACTS
- Targets Government and enterprise networks in Asia and Europe
- New tools EchoCreep and GraphWorm were added in 2025
- C2 channels Discord and Microsoft Graph API were used for control traffic
- Older malware Trochilus RAT, Gh0st RAT and 9002 RAT were previously linked to the group
The group has been tied to attacks on government agencies and companies in Russia, Georgia, Mongolia and other Asian countries, and more recently on public-sector victims in Belgium, Italy, Serbia, Poland and Spain. The disclosure said the operators also targeted a university in South Africa.
Webworm has shifted toward proxy tools and other utilities that are described as more stealthy than full backdoors. Those tools include iox, WormFrp, ChainWorm, SmuxProxy and WormSocket, with WormFrp reportedly pulling settings from a compromised Amazon S3 bucket.
EchoCreep supports file upload and download along with command execution through cmd.exe, while GraphWorm can spawn a new cmd.exe session, create a process, move files to and from Microsoft OneDrive, and stop itself after receiving a signal from operators. The earliest Discord commands seen on the channel date to March 21, 2024, and the channel has carried 433 messages.
The initial access method is not known. The report said the attackers used open-source tools such as dirsearch and nuclei to brute-force web server files and test for vulnerabilities.
WHY IT MATTERS
The findings show how a long-running espionage group is blending into common cloud and messaging services to make detection harder. They also point to continued use of living-off-the-land style utilities and custom proxies that can complicate incident response and network monitoring.

