Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft SharePoint Server CVE-2023-29357 Lets Attackers Remotely Execute Code
August 12, 2026
Critical Windows AFD.sys Zero-Day Exploited by Lazarus Group
August 12, 2026
Critical Microsoft Outlook RCE Vulnerability Patched
August 12, 2026
Home/Threats/GraphWorm Malware Exploits Microsoft OneDrive for C2 Infrastructure
Threats

GraphWorm Malware Exploits Microsoft OneDrive for C2 Infrastructure

Key Takeaways A China-aligned advanced persistent threat (APT) group, Webworm, has adopted new, stealthy malware called GraphWorm. GraphWorm leverages legitimate Microsoft OneDrive cloud...

Marcus Rodriguez
Marcus Rodriguez
May 20, 2026 4 Min Read
55 0

Key Takeaways

  • A China-aligned advanced persistent threat (APT) group, Webworm, has adopted new, stealthy malware called GraphWorm.
  • GraphWorm leverages legitimate Microsoft OneDrive cloud infrastructure for its command-and-control (C2) communications, making it difficult to detect.
  • The group, active since 2017, has expanded its targeting from Asian organizations to government entities and a university across Europe and South Africa.
  • Webworm’s updated toolkit also includes a Discord-based backdoor (Choreerp) and an extensive proxy network for enhanced anonymity.

A sophisticated China-aligned threat actor, tracked as Webworm, has significantly upgraded its operational toolkit, introducing new malware designed for enhanced stealth and evasion. The most notable addition is GraphWorm, a backdoor that innovatively exploits Microsoft OneDrive for its command-and-control (C2) infrastructure, as detailed in a recent security report.

Table Of Content

  • Key Takeaways
  • Webworm’s Evolving Threat Landscape
  • GraphWorm’s OneDrive Command and Control Mechanism
  • Webworm’s Initial Access and Proxy Infrastructure
  • What You Should Do
  • Indicators of Compromise (IoCs):-

Instead of relying on traditional, easily identifiable suspicious servers, GraphWorm embeds its malicious communications within the trusted environment of Microsoft’s cloud platform. This tactic allows the malware’s activities to blend seamlessly with legitimate cloud traffic, posing a significant challenge for conventional security measures.

Webworm’s Evolving Threat Landscape

The Webworm group has been active since at least 2017, consistently refining its attack methodologies and expanding its geographic scope. Initially focusing on organizations within Asia, the group has broadened its malicious activities to include European government bodies in Belgium, Italy, Serbia, and Poland. Furthermore, Webworm has demonstrated a widening interest by targeting a university in South Africa, indicating a global reach.

Researchers at WeLiveSecurity, who identified and analyzed these new techniques, noted a shift in Webworm’s arsenal. Previously, the group utilized well-known backdoors such as McRat and Trochilus. However, it has now transitioned to custom-built, stealthier alternatives, with GraphWorm and a Discord-based backdoor named Choreerp being prominent examples of this evolution.

GraphWorm’s OneDrive Command and Control Mechanism

GraphWorm, also known internally as OverOneDrive, is developed in Go and exclusively uses Microsoft’s Graph API for all its communications through OneDrive. This innovative approach masks its C2 traffic as routine cloud operations, allowing it to bypass many existing security detection systems.

Upon initial execution, the backdoor generates a unique identifier for each victim by combining network adapter details, processor information, and the device’s serial number. It then creates a dedicated folder in OneDrive, named with this unique ID, ensuring an isolated workspace for each compromised machine. Within this victim-specific folder, GraphWorm establishes three subfolders to manage different operational aspects: one for storing exfiltrated files, another for receiving new job instructions from the attackers, and a third for sending back the results of executed commands.

The backdoor supports a range of functionalities, including file uploads and downloads, the execution of arbitrary shell commands via cmd.exe, and the ability to adjust its sleep intervals to evade detection. Command outputs are written to a file named beaconshelloutput.txt and subsequently uploaded to OneDrive using Microsoft’s createUploadSession API endpoint. Operating entirely within this cloud environment enables GraphWorm to handle large data transfers without triggering the typical alerts associated with suspicious network activity.

Webworm’s Initial Access and Proxy Infrastructure

Webworm’s initial access tactics provide insight into how victims are first compromised. Investigations revealed that the group employs open-source tools like Nuclei, a vulnerability scanner, and dirsearch, a web path scanner, against targets across Spain, Hungary, Belgium, Nigeria, Czechia, and Serbia. Additionally, a script designed to exploit a known post-authentication remote code execution vulnerability in SquirrelMail was found in use, indicating the group’s active search for exploitable web applications.

Beyond its new backdoors, Webworm has developed an extensive proxy network to further obscure its activities. This infrastructure incorporates both open-source and custom tools, including:

  • Wormsrp: A custom fork of the popular fast reverse proxy tool, frp.
  • ChainWorm: A tool designed to chain multiple proxy hops, increasing anonymity.
  • SmuxProxy: Based on the port-forwarding tool iox.
  • WormSocket: Routes traffic through WebSocket connections.

Each of these components adds layers of indirection between the attackers and their targets, making attribution and tracing significantly more difficult.

The group also utilized a compromised Amazon S3 bucket, located at wamanharipethe.s3.ap-south-1.amazonaws.com, to host and retrieve configuration files for its proxy tools. This bucket contained sensitive data, including virtual machine snapshots with configuration data from an Italian government entity and documents exfiltrated from a Spanish government body.

What You Should Do

  • Implement robust network monitoring for unusual outbound connections to legitimate cloud storage services, as these could indicate C2 activity.
  • Regularly audit scheduled tasks and registry run keys for any unauthorized or suspicious entries.
  • Monitor process activity for instances of cmd.exe or powershell.exe downloading files from external or unusual sources.
  • Ensure all web-facing applications, particularly email and collaboration platforms, are patched and updated to the latest versions to mitigate known vulnerabilities.
  • Employ endpoint detection and response (EDR) solutions capable of detecting anomalies in legitimate cloud service usage.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-1 Hash 50433336707381429707F59C3CBE8D497D98 SearchApp.exe — Win/Agent.KBuf
SHA-1 Hash 1DF40A4A31B30B62EC33DC6FECC2C4408302ADC7 ssh.exe — Win/Hack Tool/Proxy.WQ
SHA-1 Hash 7DCFE9EE25841DFD58D3D6871BF867FE32141DFB svc.exe — MSIL/Hack Tool/Proxy.WQ
SHA-1 Hash 7F1970D620216C5FFF4E14A6CCC13FCCC267217C2 OverOneDrivev0316.exe — Win/Agent.78CV.M
SHA-1 Hash 48159A7FC2E688386864BEA59FD40DFFC4B24D6 MessengerClient.exe — MSIL/Hack Tool/Proxy.WQ
SHA-1 Hash A3C077BDF8898E612CCD65BC82E7960834ADB2A9 dsocks.exe — Win/RiskWare/iox
Domain/URL wamanharipethe.s3.ap-south-1.amazonaws.com Compromised S3 bucket used for config and data exfiltration
IP Address 45.77.13.67 Vultr Holdings — Wormsrp web server
IP Address 64.176.85.158 The Constant Company — Wormsrp web server
IP Address 104.243.23.43 Networksoc — SmuxProxy server
IP Address 108.61.200.151 Vultr Holdings — Wormsrp proxy
IP Address 144.168.60.233 Networksoc — Reverse proxy/Edison service

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwareSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Microsoft Releases Mitigation for Critical BitLocker 0-Day Vulnerability

Next Post

Hackers Abuse MSHTA Legacy Windows Tool to Deliver LummaStealer and Amatera Malware

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
DEF CON Attendees Broadcast Fake Wi-Fi Network on Flight
August 11, 2026
Critical CopyEscape Docker Vulnerability Exposes Host Files to Root Overwrite
August 11, 2026
Intel’s $20 Billion Stock Sale Sparks Debate on Chip Supply Chain Security
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us