news.mlab.sh
Back to the feed
threat-intel

Webworm: New burrowing techniques

High
Summary

This blog post details the evolving tactics of Webworm, a China-aligned APT group, particularly their activity in 2025. Webworm has shifted away from traditional backdoors in favor of more sophisticated techniques, including utilizing Discord and Microsoft Graph API for C&C communication, leveraging custom proxy tools like WormFrp and ChainWorm, and staging malware within a GitHub repository. The group uses a custom Amazon S3 bucket to exfiltrate data and employs open-source tools for web path scanning and vulnerability exploitation. The analysis reveals a significant increase in the group's operational complexity and a broadening of their targeting scope, now including governmental organizations in Belgium, Italy, Serbia, and Poland, alongside South Africa. The post highlights the group's use of legitimate tools to blend in and evade detection, and their continued expansion of their toolset.

Read the full article at WeLiveSecurity

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.