Skip to main content
Mallory
MalwareUsed by 3 actors

EchoCreep

EchoCreep is a Go-based backdoor used by the China-aligned threat actor Webworm, also tracked as Space Pirates and UAT-8302. ESET reported it as one of two new backdoors introduced in Webworm’s 2025 campaigns. EchoCreep uses Discord for command-and-control, including crafted HTTP requests to Discord APIs, and supports receiving commands, sending runtime reports, and uploading files; reporting also states it supports file download and command execution via cmd.exe. Recovered telemetry cited 433 decrypted Discord messages across four victim-specific channels, with the earliest observed commands on 2024-03-21 and the first actual compromise in recovered logs assessed on 2025-04-09. EchoCreep decodes commands with base64 and decrypts them using AES-CBC-128. A persistence artifact associated with EchoCreep is the scheduled task name "MicrosoftSSHUpdate," and related detection content references the handshake string "Up Success." One identified sample is SearchApp.exe, SHA-1 CB4E50433336707381429707F59C3CBE8D497D98, detected by ESET as WinGo/Agent.ZK. EchoCreep was observed in Webworm operations targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain, as well as activity involving a university in South Africa. The initial access and delivery mechanism for EchoCreep are reported as unknown.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Webworm

More YARA rules (in the case-folder YARA file): EchoCreep (HIGH) -- adds MicrosoftSSHUpdate task name, Up Success handshake string, and Discord-JSON field literals.

via github gist webgist.github.com
Space Pirates

According to ESET, the group’s latest campaigns introduced two new backdoors: EchoCreep and GraphWorm. EchoCreep uses Discord for C&C communication, allowing attackers to upload files, send runtime reports, and receive commands.

via help net securityhelpnetsecurity.com
UAT-8302

According to ESET, the group’s latest campaigns introduced two new backdoors: EchoCreep and GraphWorm. EchoCreep uses Discord for C&C communication, allowing attackers to upload files, send runtime reports, and receive commands.

via help net securityhelpnetsecurity.com
MITRE ATT&CK

Techniques & procedures

17 distinct techniques documented for this family, organized by ATT&CK tactic.

T1608.002Upload ToolEvidence1

Webworm staged tools in its GitHub repo for direct download onto compromised systems.

Execution

3 techniques
T1053Scheduled Task/JobEvidence1

1 persistence task name ( MicrosoftSSHUpdate )

T1053.005Scheduled TaskEvidence1

EchoCreep is executed under the custom-created MicrosoftSSHUpdate scheduled task.

T1059.003Windows Command ShellEvidence2
TacticExecution

EchoCreep and GraphWorm both use the Windows command line to execute operator commands.

Persistence

2 techniques
T1053Scheduled Task/JobEvidence1

1 persistence task name ( MicrosoftSSHUpdate )

T1053.005Scheduled TaskEvidence1

EchoCreep is executed under the custom-created MicrosoftSSHUpdate scheduled task.

T1053Scheduled Task/JobEvidence1

1 persistence task name ( MicrosoftSSHUpdate )

T1053.005Scheduled TaskEvidence1

EchoCreep is executed under the custom-created MicrosoftSSHUpdate scheduled task.

Stealth

3 techniques
T1027.013Encrypted/Encoded FileEvidence1
TacticStealth

GraphWorm and EchoCreep use encryption and encoding techniques to obfuscate data.

T1036MasqueradingEvidence1
TacticStealth

the use of a GitHub repository impersonating a WordPress fork ("github[.]com/anjsdgasdf/WordPress") as a staging ground for malware and tools like SoftEther VPN in an effort to blend in and fly under the radar.

T1070.006TimestompEvidence1
TacticStealth

EchoCreep contains a modified timestamp attribute.

Lateral Movement

1 technique
T1550.001Application Access TokenEvidence1

GraphWorm and EchoCreep use API keys to communicate with the C&C infrastructure.

Collection

1 technique
T1005Data from Local SystemEvidence1

Both EchoCreep and GraphWorm can collect data from the local system.

T1071Application Layer ProtocolEvidence3

EchoCreep uses Discord for C&C communication, allowing attackers to upload files, send runtime reports, and receive commands. GraphWorm relies on Microsoft Graph API and OneDrive endpoints to retrieve tasks and upload victim information. | By decrypting more than 400 Discord messages used for command-and-control (C&C) communication, ESET gained visibility into the group’s infrastructure and operations.

T1071.001Web ProtocolsEvidence2

EchoCreep backdoor using Discord for C&C. ... GraphWorm backdoor using the Microsoft Graph API for C&C.

T1102Web ServiceEvidence1

EchoCreep (HIGH) -- adds MicrosoftSSHUpdate task name, Up Success handshake string, and Discord-JSON field literals.

T1102.002Bidirectional CommunicationEvidence1

EchoCreep and GraphWorm use Discord and the Microsoft Graph API for C&C infrastructure.

T1105Ingress Tool TransferEvidence3

This confirms the actor delivers tools through operator-controlled open directories, not mass-mail or drive-by chains.

T1132.001Standard EncodingEvidence1

EchoCreep, GraphWorm, and WormSocket make use of base64 encoding.

T1573.002Asymmetric CryptographyEvidence1

EchoCreep, GraphWorm, WormSocket, and WormFrp use AES in some capacity.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

EchoCreep and GraphWorm exfiltrate data to their respective C&C infrastructures.

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
1 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha1●●●●●●●●●●●●View more in app14 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping17

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.

EchoCreep | Mallory