China-Linked Webworm APT Evolves Tactics, Expands to European Targets

2026-05-20T14:52:17Z23d7f17b6ecc81e6b4661877ea4bb18d56d502632f09a3e62aa7f467cbc1e681
APTAvada BuilderCypherLocDirty FragExchange ServerFDMTPFox TempestFragnesiaGitHub breachGrafanaGremlin stealerLinux kernelMicrosoft takedownMini Shai-Hulud (npm/PyPI)」「Hugging Face typosquat」「TrickMo」「TONMustang PandaTeamPCPTencShellWebwormWordPressinfostealermalicious VS Code extensionscarewaresource code theftsupply chain compromisezero-day

What happened

Mid‑May 2026 reporting highlights a wave of high‑impact cyber activity and emerging trends: China‑linked Webworm APT has expanded operations into Europe and refined espionage tactics; GitHub confirmed a breach of internal repositories via a malicious VS Code extension (claimed by TeamPCP), with downstream source‑code theft affecting projects such as Grafana; large‑scale scareware (CypherLoc) and modular infostealers (Gremlin) are evolving; multiple high‑severity vulnerabilities and zero‑days were disclosed or found (notably a severe on‑prem Exchange Server zero‑day, the Fragnesia Linux local‑L

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
23d7f17b6ecc81e6b4661877ea4bb18d56d502632f09a3e62aa7f467cbc1e681
Enrichment time
2026-05-20T14:52:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.