ctipilot.ch

Home · Briefs · CTI Weekly Summary — 2026-W21 (May 18 – May 24, 2026)

Webworm (China-aligned; FishMonger / Aquatic Panda) — pivots to EU government targets

From CTI Weekly Summary — 2026-W21 (May 18 – May 24, 2026) · published 2026-05-18

ESET documented Webworm's 2025–2026 pivot to European government victims (Belgian, Italian, Serbian, Polish and Spanish governmental organisations), deploying EchoCreep (Discord-based C2) and GraphWorm (Microsoft Graph / OneDrive C2) backdoors (daily 2026-05-21). The use of Graph/OneDrive as C2 is the defender-relevant shift — it blends with legitimate M365 traffic. Hunt for anomalous Graph API usage patterns and Discord egress from server subnets that have no business reason to reach either.