China's Webworm Uses Discord and Microsoft Graph to Infiltrate European Governments
By hiding inside platforms governments trust, Webworm has turned enterprise infrastructure into a covert espionage highway.
Written by OutOfToken AI
June 3, 2026 · 4 min read · Synthesized from reporting by Dark Reading · How this works
A China-linked advanced persistent threat group known as Webworm has pivoted its targeting westward, running sophisticated intrusion campaigns against governmental organizations across Europe. The group's toolkit is notable not for exotic zero-days, but for its deliberate abuse of legitimate, widely trusted platforms — Discord and Microsoft Graph APIs — to conduct command-and-control operations that blend seamlessly into normal enterprise traffic. It is a calculated strategy that makes detection brutally difficult and attribution even harder.
Living Off Trusted Infrastructure
Webworm's use of Discord and Microsoft Graph as C2 channels represents a maturing trend in nation-state tradecraft: living off trusted infrastructure, or LOTI. Rather than spinning up dedicated attacker-controlled servers — which generate novel network signatures that endpoint detection tools can flag — the group routes communications through platforms that IT teams already whitelist by default. Microsoft Graph API calls look identical to routine Microsoft 365 telemetry. Discord traffic travels over encrypted HTTPS on standard ports. For a security operations center analyst staring at a firewall log, the difference between a compromised workstation phoning home and a developer syncing a bot is effectively invisible without deep behavioral analytics.
SOCKS Proxies and the SoftEther Layer
Beyond the C2 obfuscation layer, Webworm further insulates its operators using SOCKS proxy tunneling, with SoftEther VPN serving as a key component. SoftEther is an open-source VPN solution originally developed for legitimate enterprise use, capable of tunneling over HTTPS, ICMP, and DNS — protocols that most perimeter defenses treat as benign. By deploying SoftEther nodes between victim networks and attacker infrastructure, Webworm inserts an additional middleman that strips direct attribution trails. Each hop in the chain adds forensic distance, complicating incident responders' ability to trace activity back to origin infrastructure. This layered approach — trusted SaaS platform on top, tunneled proxy beneath — creates a two-stage obfuscation architecture that is both operationally cheap and devastatingly effective.
"Webworm doesn't need to break through the front door when the building's own intercom system can be turned into a covert radio channel — Discord and Microsoft Graph are that intercom."
A Geographic Pivot Toward Europe
Webworm has historically concentrated its operations across Asia, but this campaign marks a deliberate strategic reorientation toward European government targets. The shift aligns with broader intelligence priorities attributed to Beijing-linked threat actors, particularly as geopolitical tensions over Taiwan, trade policy, and Ukraine-related diplomacy intensify. European governments — many of which hold sensitive NATO deliberations, sanctions enforcement data, and bilateral intelligence assessments — represent high-value espionage targets. Security researchers have not publicly confirmed which specific ministries or agencies were compromised, and attribution to Webworm specifically warrants cross-referencing against official advisories from bodies like CISA, the UK's NCSC, or ENISA before treating it as definitive. What the campaign does confirm is that the playbook of Chinese APT groups is growing more sophisticated and geographically ambitious.
Webworm's campaign is a sharp reminder that the most dangerous intrusions often leave no unusual software signatures — only suspicious patterns buried inside legitimate platform telemetry. European governments and their security vendors must move beyond perimeter-first thinking and invest in behavioral analytics capable of detecting anomalous usage of trusted services. As nation-state actors continue weaponizing the very tools enterprises rely on, the definition of 'trusted infrastructure' needs an urgent renegotiation.
Editorial Note
Dark Reading is a reputable cybersecurity publication with established track record for reporting on APT activity. The technical details about abuse of legitimate services (Discord, Microsoft Graph APIs) and tunneling tools (SoftEther VPN) align with known APT tactics documented by security researchers. However, attribution to 'Webworm' specifically and targeting of EU governments should be cross-referenced with official advisories from CISA, NCSC, or major cybersecurity firms for full verification.
Claim Tracker
AI-assessed
No source attribution provided for attribution to China; common in threat reports but requires expert verification
Specific targets and scope not detailed in excerpt; lacks independent confirmation
Technical claim not substantiated with evidence, logs, or security researcher citations in excerpt provided
Technically accurate statement about API traffic patterns; verifiable by IT professionals
Factually accurate about Discord's standard security protocols; publicly documented
Ask AI about this story
// discussion
sign in to join the discussion
