Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
A China-nexus threat actor tracked as UAT-11587 has targeted government and policy organizations across Asia and Syria using a new Rust-based Windows backdoor called Antino. The campaign relies on spear-phishing, spoofed identities, and Microsoft 365-based command-and-control through Outlook and OneDrive to deliver multi-stage malware and evade detection. #UAT11587 #Antino #Microsoft365 #Outlook #OneDrive

Keypoints

  • UAT-11587 targeted government and policy organizations in multiple Asian countries.
  • The group used the previously undocumented Antino backdoor in its attack chain.
  • Antino is a Rust-compiled Windows backdoor that operates through Microsoft 365.
  • The campaign used spoofed senders and fake Gmail attachment previews to improve phishing success.
  • Talos observed the actor using Outlook and OneDrive as dead drops for commands and file transfer.

Read More: https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html