Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Worok is the name ESET gave to a cyberespionage group it publicly described in September 2022, after observing activity dating to at least 2020. ESET reported that the group targeted public- and private-sector organizations, especially in Asia, and later characterized it as China-aligned. The word “new” belongs to the 2022 disclosure: ESET’s latest Worok-specific reporting reviewed here covers activity through March 2025, and does not establish the group’s status after that.

What is Worok?

ESET described Worok as a cyberespionage group that develops custom tools and also uses existing tools to compromise targets. Its reporting points to operations aimed at collecting information from high-profile organizations, but that motive is an assessment, not confirmed knowledge of the operators’ intent.

ESET researcher Thibaut Passilly, whom ESET identified as Worok’s discoverer, said the group appeared to seek information from victims because it targeted high-profile entities across sectors, with a particular emphasis on government. ESET’s initial 2022 report suggested possible ties to TA428 based on timing and tooling, but assigned that assessment low confidence. It should not be treated as a settled identification of Worok.

Who did Worok target, and when?

ESET’s September 2022 disclosure said it had observed Worok activity since at least late 2020. Early examples spanned several regions and sectors, rather than Asia alone:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • An East Asian telecommunications company
  • A Central Asian bank
  • A Southeast Asian maritime company
  • A Middle Eastern government entity
  • A private company in southern Africa

ESET saw a gap in its observed operations from May 2021 through January 2022. It then recorded activity in February 2022 against an energy company in Central Asia and a public-sector entity in Southeast Asia. That is a gap in ESET’s observations; it does not demonstrate that Worok’s operations stopped during those months.

In its report covering April through September 2023, ESET described Worok as China-aligned, active since at least 2020, and focused primarily on high-profile companies and local governments in Asia. The later report covering October 2024 through March 2025 documented targeting of public-sector entities and private companies in Mongolia, Kyrgyzstan, Türkiye, Taiwan, and Thailand. It also reported an attack on UK academic institutions using XMLDoor and an updated GoFighting variant used against Cambodian government institutions.

What tools did ESET associate with Worok?

ESET’s reporting describes a mix of custom malware and shared toolsets. The names below refer to tools ESET associated with the group; their presence does not by itself establish who operated a particular campaign.

Tool How ESET described it
CLRLoad A loader named in ESET’s initial 2022 description. ESET telemetry suggested PowHeartBeat replaced it in more recent campaigns as the tool used to launch PNGLoad.
PNGLoad A loader in ESET’s initial account, used in the reported chain with CLRLoad or, in later campaigns, PowHeartBeat.
PowHeartBeat A PowerShell backdoor that ESET said could replace CLRLoad as the launcher for PNGLoad.
GoFighting A Go backdoor ESET attributed to Worok in 2023, describing it as a reimplementation of PowHeartBeat. The 2023 report noted a GitHub-based network fallback; the 2024–2025 report described an updated variant using Dropbox for network communication.
XMLDoor A tool reported in ESET’s 2024–2025 coverage; ESET said Worok had used it since at least 2021.
PhantomNet and HDMan Existing, shared China-aligned toolsets that ESET said Worok used.

Why do reports differ on Worok’s attribution?

Cyberespionage attribution is often uncertain because different groups can use shared tools, infrastructure, or networks. ESET’s later reporting reassessed several campaigns that other researchers had associated with different groups, linking those campaigns to Worok with medium confidence. That is a stronger stated confidence level than ESET’s low-confidence 2022 suggestion of possible TA428 ties, but it remains an assessment rather than certainty.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ESET also reported that Worok and BackdoorDiplomacy operated in the same network during Operation Crimson Palace. ESET said its telemetry did not show the two groups sharing targets. Co-location, shared tooling, or a network overlap can inform an attribution assessment, but does not alone prove that groups have a common command structure.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about Worok’s current status?

The latest Worok-specific activity in the ESET reporting covered here is from October 2024 through March 2025. That reporting documents targets and tools during that period; it does not establish whether Worok remains active after March 2025. The 2022 description is therefore useful as the group’s original public disclosure, not as evidence that the group is newly active today.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.