Webworm APT targets European government organizations with new backdoors
2026-05-20T14:51:49Z•55b741cb264831554cc5904dc8e8943f9aa158157fcedfa8f7b17e8e70323a5a
BelgiumChina-aligned APTDarwinium SDK update","ArmorCode Anya Agents","Trust3 MCP","NanoESETEuropeFBIGitHub breachItalyPolandSerbiaSouth AfricaSpace PiratesSpainTeamPCPUAT-8302Verizon DBIRWebwormbackdoorcode exfiltrationcrypto ATM scamsinitial accesspoisoned VS Code extensionremote access scamssupply-chain compromisevulnerability exploitation
What happened
Multiple high-impact security developments: ESET attributes 2025 activity to Webworm (aka Space Pirates / UAT-8302), a China-aligned APT that has expanded from Asia into Europe and South Africa and is deploying new backdoors against government targets in Belgium, Italy, Poland, Serbia and Spain. Microsoft/GitHub confirmed a TeamPCP compromise of GitHub-internal repositories linked to a poisoned VS Code extension and reported exfiltration consistent with the attacker’s claims. Verizon’s 2026 DBIR finds vulnerability exploitation has overtaken stolen credentials as the leading initial access the
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 55b741cb264831554cc5904dc8e8943f9aa158157fcedfa8f7b17e8e70323a5a
- Enrichment time
- 2026-05-20T14:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.