Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk4 min

Does Revoking a Token Remove a Backdoor? What the GraphWorm Sample Shows

In one GraphWorm sample, an upgrade command could replace OAuth credentials and switch the OneDrive identity used for C2. Token revocation was only one part of containment.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

No—not necessarily. In a GraphWorm sample analyzed by cybersecurity analyst Yanky Wilson, the implant could receive an upgrade task that replaced its OAuth credentials and switched the OneDrive identity it used for command and control (C2). Revoking one token could remove that credential without removing the implant or its ability to reach a replacement identity. This is a sample-specific finding, not evidence that token revocation generally fails.

Why token revocation did not necessarily evict this implant

Wilson’s September 21, 2026 CSO Online article describes GraphWorm as a custom implant attributed to Webworm. In the analyzed sample, it authenticated to Microsoft Graph as an OAuth application and used a OneDrive account as a dead drop. Encrypted task files were placed in a job folder; the implant polled for them, ran received commands, and uploaded encrypted results. The reported command set included shell execution, file transfer, sleep, kill, key exchange, and upgrade. Because this activity used Microsoft’s cloud services, ordinary Microsoft 365 traffic could carry tasking and results, making network domains or ports alone an incomplete way to look for it. Wilson’s account of GraphWorm

As an Amazon Associate I earn from qualifying purchases.

The distinguishing behavior was the upgrade handler. Wilson reports that it could parse a configuration, replace credential strings, rebuild OAuth scopes, test a new OneDrive connection, save replacement configuration, and swap the live API instance. The linked detection pack identifies the replaceable fields as client_id, client_secret, tenant_id, and refresh_token. Wilson says his conclusion was checked against strings and a decompiled function. This is the analyst’s reverse-engineering finding about the examined sample, not an independently verified live incident. GraphWorm/Webworm APT Detection Pack

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

As Wilson put it, “Revocation removed a credential. It did not remove access.” In this case, the distinction is between invalidating a credential and removing malware from an endpoint: if the implant remains and can accept replacement credentials, revoking the current token alone does not establish that the endpoint is clean. MITRE ATT&CK describes application access tokens as alternate authentication material under T1550.001; that framework reference does not confirm GraphWorm’s upgrade behavior.

What to do during a suspected GraphWorm incident

For this scenario, treat credential revocation as one containment measure, not the whole response. Wilson’s recommendations are to restrict the affected endpoint’s access to the C2 channel while credentials are revoked, and to investigate the application registration or identity as a durable target. Where applicable, seek action on the relevant registration rather than assuming that invalidating one token removed the implant. These steps complement—not replace—your organization’s incident-response process, and no single action guarantees containment.

  1. Restrict the endpoint’s channel access. Limit the affected machine’s ability to reach the suspected C2 channel at the same time credentials are revoked; do not wait to see whether the operator can rotate identities.
  2. Revoke the affected credentials and investigate the application identity. Review the relevant registration and pursue action against it where appropriate. Do not treat token or session invalidation as proof that endpoint-resident code is gone.
  3. Review cloud identity and file activity. Search sign-in telemetry for the reported application identifier and unfamiliar tenant authentication. Examine OneDrive user-agent patterns and file activity for suspicious behavior.
  4. Inspect the endpoint. Look for the malware and associated behavior in endpoint telemetry. A network-only review may miss activity carried through Microsoft cloud services.
  5. Validate indicators before drawing conclusions. Check any indicator or detection rule against your organization’s telemetry and context; a match to a sample-specific IOC is not, by itself, proof of an active intrusion or complete evidence of scope.

Why identity, cloud, and endpoint evidence matter together

The reported behavior makes three evidence planes relevant. Token invalidation addresses credentials; endpoint and channel restrictions address the machine that may still run the implant; and identity/application and cloud telemetry may expose use of an application or OneDrive identity. A network indicator alone can be less informative when tasking travels through a legitimate cloud endpoint. Wilson also reports that the sample derived its victim identifier from hardware details. The detection pack specifies a MAC address and CPU and disk serials gathered through WMI, so changing a hostname, subnet, or egress identity would not necessarily make this sample lose track of a host. These are behaviors attributed to the examined sample, not universal GraphWorm guarantees.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How strong is the evidence?

The CSO Online article and the detection pack are both authored by Wilson (the repository lists Yaakov Wilson); they are not independent corroboration. The repository, dated June 16, 2026, documents one sample and says its analysis used FLOSS and Ghidra static analysis, with no sandbox detonation or PCAP data available. Its detection rules, queries, and indicators therefore describe that sample and should be validated against current organizational telemetry before being treated as operationally conclusive. The article characterizes the malware as Webworm-linked, and the repository makes the same attribution; the materials cited here do not provide separate independent confirmation of that attribution.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The repository reports that its sample was 2.15 MB, first seen May 20, 2026, and had 24/46 VirusTotal detections as represented in the June 16, 2026 pack. Those are sample metadata and a scan-time result, not evidence of how prevalent the malware is.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.