Webworm APT targets European government organizations with new backdoors

2026-05-20T14:51:49Z55b741cb264831554cc5904dc8e8943f9aa158157fcedfa8f7b17e8e70323a5a
BelgiumChina-aligned APTDarwinium SDK update","ArmorCode Anya Agents","Trust3 MCP","NanoESETEuropeFBIGitHub breachItalyPolandSerbiaSouth AfricaSpace PiratesSpainTeamPCPUAT-8302Verizon DBIRWebwormbackdoorcode exfiltrationcrypto ATM scamsinitial accesspoisoned VS Code extensionremote access scamssupply-chain compromisevulnerability exploitation

What happened

Multiple high-impact security developments: ESET attributes 2025 activity to Webworm (aka Space Pirates / UAT-8302), a China-aligned APT that has expanded from Asia into Europe and South Africa and is deploying new backdoors against government targets in Belgium, Italy, Poland, Serbia and Spain. Microsoft/GitHub confirmed a TeamPCP compromise of GitHub-internal repositories linked to a poisoned VS Code extension and reported exfiltration consistent with the attacker’s claims. Verizon’s 2026 DBIR finds vulnerability exploitation has overtaken stolen credentials as the leading initial access the

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
55b741cb264831554cc5904dc8e8943f9aa158157fcedfa8f7b17e8e70323a5a
Enrichment time
2026-05-20T14:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.