Security researchers at ESET report that Webworm, a China-aligned advanced persistent threat (APT) also tracked under names including “Space Pirates” and “UAT-8302,” remains active and has expanded beyond its earlier Asia-focused targeting. ESET says the group has been active since at least 2022 and is now reaching European government organizations. During 2025, researchers observed activity aimed at organizations in countries including Belgium, Italy, Poland, Serbia, and Spain. The reporting also describes the group as evolving its cyber-espionage tactics alongside this geographic expansion. In addition to Europe, ESET notes that Webworm activity extends to South Africa, where researchers identified activity involving a local university. The coverage across outlets is based on ESET’s analysis of Webworm’s 2025 activity, including observations of new backdoors and changes in tactics. The articles do not provide additional details on the specific vulnerabilities used, the affected systems, or confirmed impacts, but they characterize the campaign as part of ongoing efforts to compromise government-related targets.