Webworm is a China-aligned cyber-espionage group active since at least 2017. It is also tracked as Space Pirates and UAT-8302; reporting assesses Webworm and Space Pirates are likely the same entity. Webworm shares tradecraft and tooling overlaps with the China-linked FishMonger and SixLittleMonkeys clusters, but these are tracked as related clusters rather than confirmed aliases. The group has targeted government organizations and enterprises, including IT services, aerospace, and electric-power organizations, initially across Asia and Russia and Georgia and later in Europe and South Africa. Confirmed 2025 activity included government targets in Belgium, Italy, Poland, Serbia, and Spain, and a university in South Africa. Webworm has used customized versions of Trochilus, Gh0st RAT, and 9002 RAT, including altered communications and multi-stage loaders. Observed deployment techniques include DLL side-loading, token theft, User Account Control bypasses, scheduled-task execution, process injection, and in-memory execution. Its newer toolset includes the EchoCreep and GraphWorm backdoors and proxy tools such as WormFrp, ChainWorm, SmuxProxy, and WormSocket. EchoCreep uses Discord for command and control, while GraphWorm uses Microsoft Graph API and OneDrive for tasking, file transfer, and command-result collection. Webworm has used SoftEther VPN, custom and open-source proxy tooling, cloud storage, and code-hosting services to conceal command-and-control and route traffic through compromised infrastructure. The group has also conducted web-target reconnaissance and vulnerability scanning and has used tooling associated with exploitation of exposed web applications. Its operations are consistent with long-term intelligence collection, including collection of documents, infrastructure information, and credentials from compromised systems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
52 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A China-nexus APT group associated with the GraphWorm custom implant. GraphWorm authenticates to Microsoft Graph as an OAuth application and uses a OneDrive account as an encrypted dead-drop C2 channel. The implant can execute shell commands, transfer files, alter sleep behavior, terminate itself, perform key exchange, and remotely replace its complete OAuth credential configuration through an “upgrade” command, allowing C2 identity rotation after token revocation.
Used legitimate platforms for command-and-control, deploying backdoors via Discord and the Microsoft Graph API.
Chinese state-linked group noted here for shared tradecraft and use of the Trochilus codebase alongside FishMonger and SixLittleMonkeys.
Chinese threat actor linked in the article through use of Trochilus and noted to share tradecraft commonalities with FishMonger and SixLittleMonkeys.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.