Webworm Deploys Discord‑Based Backdoors Using Microsoft Graph API for C2
Inspect Discord traffic for suspicious commands and audit Microsoft Graph API usage to detect Webworm backdoors.
Inspect Discord traffic for suspicious commands and audit Microsoft Graph API usage to detect Webworm backdoors.
Summary
Security researchers have identified new activity from the China‑aligned threat actor Webworm, which has been active since at least 2022.
Webworm deploys custom backdoors that use Discord and Microsoft Graph API for command‑and‑control communications.
The backdoors are designed to blend in with legitimate traffic, making detection difficult.
The threat actor primarily targets government agencies, as documented by Broadcom‑owned Symantec in September 2022.
The use of Discord as a C2 channel is a novel technique that leverages the platform’s real‑time messaging capabilities.
Microsoft Graph API abuse allows the attackers to harvest user data and issue privileged commands.
Organizations should audit Discord traffic and monitor Graph API usage for suspicious activity.
Key changes
- Webworm uses Discord and Microsoft Graph API for C2
- Deploys custom backdoors
- Active since at least 2022
- Targets government agencies
- Discovered by Broadcom‑owned Symantec in 2022
- Uses Discord real‑time messaging for C2