Nation-stateMay 22, 2026
China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts.
Webworm APT targets EU governments using Discord and Microsoft Graph for C2.
Vendor Watch
Run Discord?
Get an email when a reviewed story names Discord, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
The Chinese APT group Webworm has been targeting EU governments, leveraging Discord and Microsoft Graph for command and control. The group also uses SOCKS proxies like SoftEther VPN to obscure their activity.
Entities
Webworm (threat_actor)Discord (product)Microsoft Graph (product)SoftEther VPN (product)