Researchers identify fresh 2025 activity from China-aligned threat actor deploying EchoCreep and GraphWorm backdoors through popular cloud services.
- Webworm threat actor deployed custom EchoCreep and GraphWorm backdoors in 2025 campaigns
- Backdoors use Discord and Microsoft Graph API for command-and-control communications
- Group has targeted government agencies since at least 2022
Cybersecurity researchers have documented new activity from the China-aligned threat actor Webworm, which deployed custom backdoors using Discord and Microsoft Graph API for command-and-control operations during 2025.
The threat group, according to researchers, deployed two distinct backdoors named EchoCreep and GraphWorm that leverage popular cloud services to evade detection.
Webworm was first publicly documented by Broadcom-owned Symantec in September 2022 and has been active since at least 2022, primarily targeting government agencies.
The use of legitimate cloud services like Discord and Microsoft Graph API represents a common tactic among sophisticated threat actors to blend malicious traffic with normal business communications. By leveraging these trusted platforms, attackers can bypass traditional network security controls that might block connections to suspicious domains.
The EchoCreep and GraphWorm backdoors appear designed for persistent access and data collection within compromised networks. The choice of Discord and Microsoft Graph API as communication channels suggests the attackers are adapting their infrastructure to use widely-deployed business services.
Government agencies remain a primary target for Webworm operations, continuing a pattern established since the group’s initial identification. The targeting aligns with broader Chinese state-sponsored cyber espionage campaigns focused on intelligence collection from government networks.
The 2025 activity represents continued evolution in Webworm’s tactics, techniques and procedures, demonstrating the group’s ongoing development of new tools and methods for maintaining persistent access to target environments.
Why It Matters
This development highlights the challenge CISOs face when legitimate cloud services are weaponised for malicious purposes. Traditional network security controls may struggle to identify malicious traffic flowing through trusted platforms like Discord and Microsoft Graph API. Government agencies and organisations with similar risk profiles should review their monitoring capabilities for these services and consider additional controls for cloud-based communications platforms.
What To Do Now
- Review network monitoring for unusual Discord and Microsoft Graph API traffic patterns, as documented in the research
- Assess current security controls for legitimate cloud service abuse scenarios
- Evaluate endpoint detection capabilities for custom backdoor deployment
