Actor Profile
Webworm is a China-aligned advanced persistent threat (APT) actor first documented by Symantec in September 2022, with activity traced back to at least 2022. The group is motivated by espionage objectives, focusing on intelligence collection from government entities. Webworm demonstrates operational sophistication through the development of custom malware toolsets and the abuse of legitimate cloud services for command-and-control infrastructure, reflecting a strategic effort to evade detection and blend malicious traffic with normal enterprise communications.
TTPs (Tactics, Techniques, Procedures)
Webworm employs custom backdoors EchoCreep and GraphWorm for persistent access and remote control. The group leverages legitimate cloud platforms—Discord and Microsoft Graph API—for C2 communications, a technique that complicates network-based detection (T1071.001: Application Layer Protocol - Web Protocols). This abuse of trusted services allows adversary traffic to blend with legitimate organizational activity. The deployment of multiple custom backdoors suggests capabilities in malware development (T1587.001: Develop Capabilities - Malware) and indicates a focus on establishing redundant access mechanisms for long-term espionage operations.
Targets & Patterns
Webworm targets government agencies, consistent with a strategic intelligence collection mandate aligned with Chinese state interests. Government sector targeting suggests the actor seeks access to sensitive policy information, diplomatic communications, and national security data. The focus on government entities reflects a pattern common among China-aligned APT groups, where espionage operations support geopolitical and economic objectives. The continued activity into 2025 indicates sustained operational tempo and prioritization of these targets for long-term intelligence gathering.
Historical Context
Webworm was first publicly documented by Symantec in September 2022, with activity dating back to at least 2022. The 2025 campaign represents a continuation of the group's operations with updated tooling, specifically the introduction of EchoCreep and GraphWorm backdoors. This evolution demonstrates the actor's ongoing investment in custom malware development and adaptation of C2 techniques to leverage contemporary cloud services. The sustained focus on government targets across multiple years indicates a persistent espionage mandate rather than opportunistic activity.
Defensive Recommendations
- Monitor and baseline Discord and Microsoft Graph API traffic patterns; investigate anomalous API calls, unusual data volumes, or connections from non-standard endpoints (T1071.001)
- Implement application control policies to restrict unauthorized use of collaboration platforms like Discord on sensitive networks, particularly in government environments
- Deploy endpoint detection rules for suspicious process execution chains associated with backdoor deployment, including unusual parent-child relationships and persistence mechanisms
- Conduct regular threat hunting for custom malware indicators associated with EchoCreep and GraphWorm, including file hashes, network signatures, and behavioral patterns
- Enforce conditional access policies and monitor OAuth token usage for Microsoft Graph API to detect potential abuse for C2 communications
---
# Geopolitical Context
Geopolitical Context
Webworm's continued operations reflect the sustained cyber espionage priorities of China-aligned threat actors against government targets. The group's evolution since 2022 demonstrates persistent investment in tooling and tradecraft refinement. The use of legitimate cloud services—Discord and Microsoft Graph API—for command-and-control infrastructure is consistent with broader trends among state-aligned actors seeking to evade detection by blending malicious traffic with trusted platforms. This activity aligns with long-standing patterns of Chinese cyber espionage focused on strategic intelligence collection from government entities, likely supporting diplomatic, economic, and national security objectives.
State Actor Alignment
Webworm is assessed to be aligned with Chinese state interests, based on targeting patterns and operational behavior documented since 2022. While specific attribution to a particular ministry or unit has not been publicly disclosed, the focus on government agencies is consistent with intelligence collection priorities associated with China's security apparatus. The group's sustained activity and access to custom malware development resources suggest institutional backing. No specific sanctions designations have been publicly linked to Webworm as of early 2025, though the activity may fall within the scope of existing frameworks addressing Chinese cyber espionage operations.
Business Impacty pro region
The targeting of government agencies carries implications for diplomatic and intelligence security across multiple regions. If Webworm's operations extend beyond a single jurisdiction, allied governments may face coordinated collection efforts aimed at policy deliberations, diplomatic communications, and sensitive administrative data. European institutions, particularly those engaged in China-related policy or technology governance, may represent attractive targets given geopolitical tensions over trade, technology transfer, and human rights. Indo-Pacific nations with strategic significance to Beijing's regional interests are also likely within scope. The abuse of widely deployed commercial platforms like Microsoft Graph API complicates defensive efforts for government networks globally, as blocking such services may disrupt legitimate operations.
Forecast
If Webworm maintains operational security and continues refining its toolset, further intrusions into government networks are likely in the coming months. Defenders should anticipate that the group may expand its abuse of trusted cloud services for C2, potentially incorporating additional platforms to diversify infrastructure and complicate attribution. If geopolitical tensions between China and Western nations escalate—particularly around technology policy, Taiwan, or South China Sea disputes—intelligence collection operations by groups like Webworm may intensify. Conversely, if diplomatic engagement increases, such activity may persist but adopt lower profiles to avoid public exposure. Enhanced information sharing among targeted governments and cloud service providers will be critical to disrupting these operations.
