Intel Chain
Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or C&C) communications. Webworm, first publicly documented by Broadcom-owned Symantec in September 2022, is assessed to be active since at least 2022, targeting government agencies Source: The Hacker News
Evidence Chain (1 linked intel)
While the numbers are modest, the crackdown on cybercrime involved 13 countries in the MENA region, the largest law enforcement collaboration to date. Source: darkreading
The spy scandal has revived fears that Austria remains a hotbed of Russian espionage activity. Source: BBC News
Have related intel?
Corroborate, contradict, or expand this intelligence chain.