Antino Backdoor Exploits Microsoft 365 in Asia Espionage Campaign
Original source
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
The Hacker News →A China-nexus threat actor, tracked as UAT-11587, has been targeting government and policy organizations across Asia with a new Rust-compiled backdoor called Antino. Deployed via spear-phishing campaigns, Antino uses Outlook and OneDrive for command-and-control (C2) operations, leveraging Microsoft Graph for communication. The campaign has affected entities in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, with a notable spike in attacks between March and June 2026. Antino supports host reconnaissance, shell and PowerShell execution, file transfer, and persistence, and has been linked to extensive reconnaissance of target organizations to tailor lures effectively. The threat actor has also targeted organizations in Syria, indicating a broader focus beyond Asia.
Read the full article
Continue reading at The Hacker News →This is an AI-generated summary. Read the original for the full story.