Webworm hides command traffic in Discord and Microsoft Graph
ESET reports that the APT group Webworm has adopted techniques that embed command-and-control and data traffic inside legitimate services such as Discord and Microsoft Graph. The group also uses custom backdoors and proxy tooling to route commands through trusted cloud platforms.
The effect is that malicious activity blends with normal enterprise API traffic, making it harder to detect and easier to maintain persistent access.
What this means for your business
Many organisations have built detection around where traffic is going. When the attacker uses the same services the business itself depends on, that model collapses. You then have to look at who is talking, under which application permission and in what pattern, rather than at the domain name. This is a direct consequence of moving the business to cloud, and it should be reflected in the monitoring architecture.
Berigo recommends
- Review the application registrations and API permissions in your Microsoft tenant, and remove those nobody can account for.
- Monitor Graph activity at application level, not just user sign-ins.
- Decide whether services such as Discord should be reachable from production environments at all.
- Test your detection against a scenario where outbound traffic goes to a domain you already trust.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch