Webworm Cyber Threat Actor: Targets, Tools, and Tactics
This cyber intelligence report analyzes Webworm, a threat actor active since 2017 that has targeted government networks and key industries across Asia, including Russia and Mongolia. The report covers Webworm's primary targets in energy, IT services, and aerospace; its use of dropper malware and customized remote access Trojans such as Trochilus, Gh0st, and the 9002 RAT; and its operational tactics, including decoy documents and modified legacy malware to evade detection. The report concludes with an assessment of the threat's significance and a proposed mitigation strategy centered on moving away from vulnerable Windows-based systems.
- Executive Summary: Overview of Webworm threat and proposed response
- Actor and Targets: Who Webworm targets and where
- Intentions: Inferred goals behind RAT deployment
- Tools and Malware: Dropper malware and evasion tactics used
- RAT Variants: Trochilus, Gh0st, and 9002: Technical breakdown of three RAT tools
- Assessment and Recommendations: Threat significance and mitigation strategy
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- The report follows a structured intelligence format — actor, targets, intentions, tools, and assessment — which makes findings easy to navigate and act upon.
- Each RAT variant (Trochilus, Gh0st, 9002) is introduced with historical context and a specific capability, grounding the threat analysis in concrete technical detail.
- The executive summary efficiently condenses the full report into a standalone brief, demonstrating awareness of professional intelligence writing conventions.
Key academic technique demonstrated
The paper demonstrates intelligence framing, organizing information around the classic Who, What, When, Where, Why, How, and So What structure. This analytical scaffolding ensures the report remains action-oriented rather than purely descriptive, culminating in a policy-relevant recommendation.
Structure breakdown
The report opens with an executive summary, then proceeds through discrete labeled sections: actor identification, target profile, inferred intentions, malware toolset analysis (with subsections per RAT), and a closing assessment with a recommended mitigation strategy. The structure mirrors professional threat intelligence reports used in cybersecurity practice.
Executive Summary
In 2017, a new cyber threat actor called Webworm began targeting government networks in Asia with customized malware. To date, the group has attacked networks in Russia, Mongolia, and several other countries in the region. The industries targeted include energy, IT services, and aerospace. Webworm's ultimate goal is to take control of networks, steal information, or gain access to computers. This is a significant problem for the affected countries because it exposes them to potentially malicious software. One possible solution is for these countries to rethink their use of vulnerable Windows-based systems and transition to more secure operating systems. This would help mitigate the risk posed by Webworm and other cyber threat actors.
Actor and Targets
Webworm is a threat actor that has been active since 2017, operating primarily against Asian countries. Webworm has primarily targeted Asian governments, agencies, and industries — ranging from IT services to aerospace and electric power plants — in countries including Russia and Mongolia. According to Broadcom Software, Webworm uses Windows-based remote access Trojans to compromise IT service providers.
Intentions
The precise intentions of the group remain unclear, but their actions reveal much. Remote access Trojans (RATs) are a type of malware that allows attackers to gain control of a victim's computer. RATs can be used to steal sensitive information, install additional malicious software, or hijack the victim's webcam. Although RATs are often deployed by cybercriminals, they can also be used by government agencies and other entities for surveillance and related purposes. Because of the significant risks posed by RATs, it is important for users to be aware of the dangers they present and to take steps to protect themselves from these threats.
Create your account
Always verify citation format against your institution’s current style guide requirements.