Tag
high
threat
Webworm APT Updates TTPs with Discord and Microsoft Graph C2
2 rules 10 TTPs 1 CVE 1 IOCThe Webworm APT group is using updated tactics, techniques, and procedures, including new backdoors using Discord and Microsoft Graph API for command and control, custom proxy tools, and GitHub for malware staging, shifting focus to European governmental organizations.
Microsoft Graph API +4
Webworm
apt
discord
proxy tool
2r
10t
1c
1i
medium
advisory
GSuite Email with Known Abuse Web Service Links
2 rules 1 TTP 2 IOCsThis analytic detects emails in Gsuite containing links to known abuse web services such as Pastebin, Telegram, and Discord, commonly used by attackers to deliver malicious payloads leading to malware, phishing, or other harmful activities.
GSuite +1
phishing
malware
pastebin
telegram
discord
2r
1t
2i