China-nexus hackers use Microsoft 365 as covert command-and-control for new Antino backdoor
TLDR
- Cisco Talos uncovered an 11-month espionage campaign by a China-nexus actor it tracks as UAT-11587, deploying a previously undocumented Rust-compiled Windows backdoor codenamed Antino.
- Antino's native command-and-control channel runs exclusively through Microsoft 365, using Microsoft Graph to poll an attacker-controlled Outlook mailbox for commands and OneDrive for implant registration, heartbeats and file exfiltration.
- The campaign has hit government, diplomatic, legislative and policy organisations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria, compromising roughly 350 endpoints.
- Talos assesses UAT-11587 as China-nexus with high confidence, citing Simplified Chinese lure metadata, a UTC+08:00 message header time zone, and Cargo build paths referencing a mainland Chinese crates.io mirror.
Cisco Talos said UAT-11587 was first detected in September 2025 targeting Taiwan's academic, think tank and civil-society policy community with spear-phishing lures, before expanding to 16 entities across eight Asian countries.1 By July 2026 the investigation had identified at least 10 confirmed and five probable affected institutional environments, with roughly 350 compromised endpoints found overall; attacks spiked between March and early June 2026, including a concentrated wave on 8 and 9 June that hit about 57 newly observed endpoints linked to India.2
Researcher Ashley Shen said Antino "supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence," with its command-and-control running natively over Microsoft Graph.1 Antino polls an attacker-controlled Outlook mailbox for new commands every 10 seconds and uploads heartbeat data to OneDrive every minute, with traffic terminating at Microsoft domains commonly allow-listed in enterprise environments.2 The initial infection stage uses Cloudflare Pages to host malicious HTA or WSF files and an execution-tracking endpoint, while Cloudflare R2 and Amazon CloudFront deliver encoded loader stages and decoy documents.2
Talos said UAT-11587 shares some overlap with Jewelbug, a China-based hackers-for-hire group that Broadcom-owned Symantec and Carbon Black characterised in an August 2026 report as running both espionage operations and a for-profit cryptocurrency fraud business, but Talos found no link between UAT-11587's espionage activity and Jewelbug's financially motivated operations and designated it a separate cluster.1 A JavaScript downloader tied to UAT-11587 referenced a CloudFront domain previously flagged by Arctic Wolf in a campaign by China-affiliated actor UNC6384 against European diplomatic and government targets.1 Evidence also showed UAT-11587 targeting organisations in Syria around May 2026, beyond its initial Asia focus.1
Why it matters: running command-and-control entirely inside Outlook and OneDrive traffic lets this backdoor hide in exactly the Microsoft 365 activity that enterprise security tools are built to trust, across a target list that spans government, defence and civil-society organisations in eight countries.