GraphWorm backdoor survives token revocation via OneDrive C2
A researcher analyzed GraphWorm, an implant tied to the China-nexus APT group Webworm. It uses OneDrive and Microsoft Graph as its C2 channel, and an upgrade command swaps all credentials on the fly, so revoking tokens only delays the attack.
- GraphWorm has no C2 domain: tasks and results move through OneDrive folders over graph.microsoft.com
- The binary stores a client ID, client secret, tenant ID and a 1,300+ character refresh token in cleartext
- An upgrade command wipes five credential strings and installs new ones, changing identity without touching the file on disk
- The implant identifies victims by hashing the MAC address and CPU and disk serial numbers, not the hostname
Read next
Security