Security researchers at ESET report that Webworm, a China-aligned advanced persistent threat (APT) also tracked under names including “Space Pirates” and “UAT-8302,” remains active and has expanded beyond its earlier Asia-focused targeting. ESET says the group has been active since at least 2022 and is now reaching European government organizations. During 2025, researchers observed activity aimed at organizations in countries including Belgium, Italy, Poland, Serbia, and Spain. The reporting also describes the group as evolving its cyber-espionage tactics alongside this geographic expansion. In addition to Europe, ESET notes that Webworm activity extends to South Africa, where researchers identified activity involving a local university. The coverage across outlets is based on ESET’s analysis of Webworm’s 2025 activity, including observations of new backdoors and changes in tactics. The articles do not provide additional details on the specific vulnerabilities used, the affected systems, or confirmed impacts, but they characterize the campaign as part of ongoing efforts to compromise government-related targets.
Webworm APT expands European government targeting, ESET reports new backdoors
Security researchers at ESET report that Webworm, a China-aligned advanced persistent threat (APT) also tracked under names including “Space Pirates” and “UAT-8302,” remains active and has expanded be...
- ESET reports the China-aligned Webworm APT is active since at least 2022.
- ESET identifies “new backdoors” and evolving tactics in Webworm’s 2025 activity.
- In 2025, Webworm targets European government organizations in Belgium, Italy, Poland, Serbia, and Spain.
- ESET also reports Webworm activity in South Africa, including involvement connected to a local university.
- Webworm is tracked by multiple names, including Space Pirates and UAT-8302.
ESET has released an analysis of the 2025 activity of Webworm, a China-aligned APT group tracked as Space Pirates and UAT-8302. Active since at least 2022, the group initially focused on targets in Asia, but has recently expanded its operations into Europe. ESET observed Webworm targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. The group also expanded its activity into South Africa, where researchers identified activity involving a local university. Discord … More → The post Webworm APT targets European government organizations with new backdoors appeared first on Help Net Security.
3 months agoChina-linked Webworm APT expands beyond Asia, targeting European government organizations and refining its cyber espionage tactics, according to ESET research
3 months agoSmith and Cox help England recover to 248-9 on truncated first day at Lord’s
England recover from early trouble on the first day of the second Test against Pakistan at Lord’s, finishing on 248-9 af...
Packers sign veteran tight end Jonnu Smith to a one-year deal
The Green Bay Packers are signing veteran tight end Jonnu Smith, adding depth to their tight end group. The agreement is...
Hull FC winger Tom Briscoe to retire at end of Super League season
Hull FC winger Tom Briscoe is set to retire at the end of the Super League season. Both outlets report that the decision...