A China-nexus threat actor tracked as UAT-11587 has targeted government and policy organizations across Asia and Syria using a new Rust-based Windows backdoor called Antino. The campaign relies on spear-phishing, spoofed identities, and Microsoft 365-based command-and-control through Outlook and OneDrive to deliver multi-stage malware and evade detection. #UAT11587 #Antino #Microsoft365 #Outlook #OneDrive
Keypoints
- UAT-11587 targeted government and policy organizations in multiple Asian countries.
- The group used the previously undocumented Antino backdoor in its attack chain.
- Antino is a Rust-compiled Windows backdoor that operates through Microsoft 365.
- The campaign used spoofed senders and fake Gmail attachment previews to improve phishing success.
- Talos observed the actor using Outlook and OneDrive as dead drops for commands and file transfer.
Read More: https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html