Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API

Cybersecurity researchers have flagged fresh activity from a Chinaaligned threat actor known as Webworm in 2025 deploying custom backdoors that employ Discord and Microsoft Graph API for commandandcontrol C2 or CC communications Webworm first publicly documented by Broadcomowned Symantec in September 2022 is assessed to be active since at least 2022 targeting government agencies