China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts.
A China-aligned Advanced Persistent Threat (APT) group known as Webworm has shifted its focus from Asia to targeting European governmental organizations, specifically in Belgium, Italy, Serbia, Spain, Poland, and South Africa. The group utilizes novel command-and-control (C2) mechanisms, including Discord and the Microsoft Graph API, alongside proxy tools like SoftEther VPN and custom solutions, to evade detection. This activity highlights a trend among threat actors to leverage legitimate tools for stealthy operations and underscores the importance of robust network monitoring and vulnerability management.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
