news.mlab.sh
Back to the feed
threat-intel

China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts.

High
Image: Dark Reading
Summary

A China-aligned Advanced Persistent Threat (APT) group known as Webworm has shifted its focus from Asia to targeting European governmental organizations, specifically in Belgium, Italy, Serbia, Spain, Poland, and South Africa. The group utilizes novel command-and-control (C2) mechanisms, including Discord and the Microsoft Graph API, alongside proxy tools like SoftEther VPN and custom solutions, to evade detection. This activity highlights a trend among threat actors to leverage legitimate tools for stealthy operations and underscores the importance of robust network monitoring and vulnerability management.

Read the full article at Dark Reading

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.