GraphWorm Malware Exploits Microsoft OneDrive for C2 Infrastructure
Key Takeaways A China-aligned advanced persistent threat (APT) group, Webworm, has adopted new, stealthy malware called GraphWorm. GraphWorm leverages legitimate Microsoft OneDrive cloud...
Key Takeaways
- A China-aligned advanced persistent threat (APT) group, Webworm, has adopted new, stealthy malware called GraphWorm.
- GraphWorm leverages legitimate Microsoft OneDrive cloud infrastructure for its command-and-control (C2) communications, making it difficult to detect.
- The group, active since 2017, has expanded its targeting from Asian organizations to government entities and a university across Europe and South Africa.
- Webworm’s updated toolkit also includes a Discord-based backdoor (Choreerp) and an extensive proxy network for enhanced anonymity.
A sophisticated China-aligned threat actor, tracked as Webworm, has significantly upgraded its operational toolkit, introducing new malware designed for enhanced stealth and evasion. The most notable addition is GraphWorm, a backdoor that innovatively exploits Microsoft OneDrive for its command-and-control (C2) infrastructure, as detailed in a recent security report.
Table Of Content
Instead of relying on traditional, easily identifiable suspicious servers, GraphWorm embeds its malicious communications within the trusted environment of Microsoft’s cloud platform. This tactic allows the malware’s activities to blend seamlessly with legitimate cloud traffic, posing a significant challenge for conventional security measures.
Webworm’s Evolving Threat Landscape
The Webworm group has been active since at least 2017, consistently refining its attack methodologies and expanding its geographic scope. Initially focusing on organizations within Asia, the group has broadened its malicious activities to include European government bodies in Belgium, Italy, Serbia, and Poland. Furthermore, Webworm has demonstrated a widening interest by targeting a university in South Africa, indicating a global reach.
Researchers at WeLiveSecurity, who identified and analyzed these new techniques, noted a shift in Webworm’s arsenal. Previously, the group utilized well-known backdoors such as McRat and Trochilus. However, it has now transitioned to custom-built, stealthier alternatives, with GraphWorm and a Discord-based backdoor named Choreerp being prominent examples of this evolution.
GraphWorm’s OneDrive Command and Control Mechanism
GraphWorm, also known internally as OverOneDrive, is developed in Go and exclusively uses Microsoft’s Graph API for all its communications through OneDrive. This innovative approach masks its C2 traffic as routine cloud operations, allowing it to bypass many existing security detection systems.
Upon initial execution, the backdoor generates a unique identifier for each victim by combining network adapter details, processor information, and the device’s serial number. It then creates a dedicated folder in OneDrive, named with this unique ID, ensuring an isolated workspace for each compromised machine. Within this victim-specific folder, GraphWorm establishes three subfolders to manage different operational aspects: one for storing exfiltrated files, another for receiving new job instructions from the attackers, and a third for sending back the results of executed commands.
The backdoor supports a range of functionalities, including file uploads and downloads, the execution of arbitrary shell commands via cmd.exe, and the ability to adjust its sleep intervals to evade detection. Command outputs are written to a file named beaconshelloutput.txt and subsequently uploaded to OneDrive using Microsoft’s createUploadSession API endpoint. Operating entirely within this cloud environment enables GraphWorm to handle large data transfers without triggering the typical alerts associated with suspicious network activity.
Webworm’s Initial Access and Proxy Infrastructure
Webworm’s initial access tactics provide insight into how victims are first compromised. Investigations revealed that the group employs open-source tools like Nuclei, a vulnerability scanner, and dirsearch, a web path scanner, against targets across Spain, Hungary, Belgium, Nigeria, Czechia, and Serbia. Additionally, a script designed to exploit a known post-authentication remote code execution vulnerability in SquirrelMail was found in use, indicating the group’s active search for exploitable web applications.
Beyond its new backdoors, Webworm has developed an extensive proxy network to further obscure its activities. This infrastructure incorporates both open-source and custom tools, including:
- Wormsrp: A custom fork of the popular fast reverse proxy tool, frp.
- ChainWorm: A tool designed to chain multiple proxy hops, increasing anonymity.
- SmuxProxy: Based on the port-forwarding tool iox.
- WormSocket: Routes traffic through WebSocket connections.
Each of these components adds layers of indirection between the attackers and their targets, making attribution and tracing significantly more difficult.
The group also utilized a compromised Amazon S3 bucket, located at wamanharipethe.s3.ap-south-1.amazonaws.com, to host and retrieve configuration files for its proxy tools. This bucket contained sensitive data, including virtual machine snapshots with configuration data from an Italian government entity and documents exfiltrated from a Spanish government body.
What You Should Do
- Implement robust network monitoring for unusual outbound connections to legitimate cloud storage services, as these could indicate C2 activity.
- Regularly audit scheduled tasks and registry run keys for any unauthorized or suspicious entries.
- Monitor process activity for instances of
cmd.exeorpowershell.exedownloading files from external or unusual sources. - Ensure all web-facing applications, particularly email and collaboration platforms, are patched and updated to the latest versions to mitigate known vulnerabilities.
- Employ endpoint detection and response (EDR) solutions capable of detecting anomalies in legitimate cloud service usage.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-1 Hash | 50433336707381429707F59C3CBE8D497D98 |
SearchApp.exe — Win/Agent.KBuf |
| SHA-1 Hash | 1DF40A4A31B30B62EC33DC6FECC2C4408302ADC7 |
ssh.exe — Win/Hack Tool/Proxy.WQ |
| SHA-1 Hash | 7DCFE9EE25841DFD58D3D6871BF867FE32141DFB |
svc.exe — MSIL/Hack Tool/Proxy.WQ |
| SHA-1 Hash | 7F1970D620216C5FFF4E14A6CCC13FCCC267217C2 |
OverOneDrivev0316.exe — Win/Agent.78CV.M |
| SHA-1 Hash | 48159A7FC2E688386864BEA59FD40DFFC4B24D6 |
MessengerClient.exe — MSIL/Hack Tool/Proxy.WQ |
| SHA-1 Hash | A3C077BDF8898E612CCD65BC82E7960834ADB2A9 |
dsocks.exe — Win/RiskWare/iox |
| Domain/URL | wamanharipethe.s3.ap-south-1.amazonaws.com |
Compromised S3 bucket used for config and data exfiltration |
| IP Address | 45.77.13.67 |
Vultr Holdings — Wormsrp web server |
| IP Address | 64.176.85.158 |
The Constant Company — Wormsrp web server |
| IP Address | 104.243.23.43 |
Networksoc — SmuxProxy server |
| IP Address | 108.61.200.151 |
Vultr Holdings — Wormsrp proxy |
| IP Address | 144.168.60.233 |
Networksoc — Reverse proxy/Edison service |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.