chiprook
← Security
SecuritySeptember 21, 2026, 16:00

GraphWorm backdoor survives token revocation via OneDrive C2

A researcher analyzed GraphWorm, an implant tied to the China-nexus APT group Webworm. It uses OneDrive and Microsoft Graph as its C2 channel, and an upgrade command swaps all credentials on the fly, so revoking tokens only delays the attack.

GraphWorm backdoor survives token revocation via OneDrive C2
#Microsoft#OneDrive#GraphWorm#Webworm
Read next
Security

Siemba brings continuous IDOR testing to production APIs

Security

CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog

Security

Revolut Customers Hit by Phishing Wave After Data Breach

Security

OpenAI and 116 firms call for collective action on AI cyber defense