Nation-State Cyber Threats
Webworm's New Backdoors Run on Discord and Microsoft OneDrive — and the China-Aligned APT Has Pivoted to Five European Governments
ESET documented Webworm, a China-aligned APT that pivoted from Asia to European governments. Its two new backdoors — EchoCreep and GraphWorm — run command-and-control entirely on Discord and Microsoft OneDrive, hiding inside the trusted cloud traffic every enterprise allowlists.