Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Antino Backdoor Utilizes Microsoft 365 in Espionage

Antino Backdoor Utilizes Microsoft 365 in Espionage

Posted on October 2, 2026 By CWS

A sophisticated cyber espionage campaign, attributed to a China-linked threat actor, is targeting government and policy organizations throughout Asia by deploying a novel backdoor called Antino. This malware uses Microsoft 365 tools like Outlook and OneDrive for command-and-control operations, raising concerns across the region.

Antino Backdoor and Its Targets

The Antino backdoor was detected as part of a spear-phishing operation initially aimed at Taiwan’s academic and policy sectors in September 2025. Since then, it has expanded its scope to infiltrate 16 entities across eight countries including India, the Philippines, and Thailand. The campaign, tracked by Cisco Talos as UAT-11587, employs the Rust-compiled Antino malware, capable of conducting host reconnaissance, executing commands, and maintaining persistence.

Antino’s reliance on Microsoft 365 involves using Microsoft Graph to communicate through Outlook and OneDrive, avoiding conventional command-and-control servers that are easier to detect. This strategy complicates efforts to trace the origin of attacks while allowing continuous data exchange with compromised networks.

Links to Other Threat Actors

Although UAT-11587 shares tactical similarities with other China-aligned groups such as Jewelbug, Cisco Talos has not confirmed any direct financial motivations linking the two. Jewelbug has been identified by Symantec and Carbon Black as a group engaging in both espionage and cryptocurrency fraud. Despite these connections, UAT-11587 is classified as a distinct entity, focusing primarily on espionage activities.

Evidence pointing to a China nexus includes Simplified Chinese metadata in phishing documents and tactics consistent with Chinese cyber operational interests. The campaign’s targets align with those typically pursued by China-based actors, focusing on political and governmental entities.

Technical Insights and Social Engineering

The Antino backdoor is notable for its exploitation of the Windows Scripted Diagnostics framework to run PowerShell commands discreetly. This method complicates the ability to attribute activities directly to the malware. Additionally, the group has employed sophisticated social engineering tactics, such as mimicking Gmail’s attachment preview to deceive recipients.

UAT-11587’s spear-phishing emails are carefully crafted, often impersonating trusted senders to bypass email security protocols like SPF and DMARC. The attack chain consists of multiple steps, from downloading a JavaScript decryptor to loading the Antino malware, ultimately using legitimate Microsoft-signed binaries for stealthy operations.

Implications and Future Outlook

This campaign underscores the evolving nature of cyber threats, where state-linked actors leverage legitimate platforms to conduct stealthy operations. The use of common platforms like Microsoft 365 highlights the necessity for organizations to enhance their cybersecurity measures, particularly in sectors vulnerable to state-sponsored espionage.

As this campaign unfolds, affected regions must remain vigilant and adapt to the dynamic threat landscape. Organizations are encouraged to bolster their security postures, focusing on email security and advanced threat detection to mitigate such sophisticated attacks.

The Hacker News Tags:Antino, Asia, Backdoor, China, cyber attack, Cybersecurity, Espionage, Microsoft 365, OneDrive, Outlook, security threats, spear-phishing, UAT-11587

Post navigation

Previous Post: OpenClaw Unveils Free AI Agent Management Platform
Next Post: WordPress Backups Expose Valuable AWS and Email Credentials

Related Posts

Rethinking AI Data Security: A Buyer’s Guide  Rethinking AI Data Security: A Buyer’s Guide  The Hacker News
VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code The Hacker News
OkoBot Malware Targets Ledger, Trezor Wallets OkoBot Malware Targets Ledger, Trezor Wallets The Hacker News
Microsoft Exposes AutoJack Exploit in AI Browsing Agents Microsoft Exposes AutoJack Exploit in AI Browsing Agents The Hacker News
Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access The Hacker News
OXLOADER Exploits Malicious Ads to Spread CastleStealer OXLOADER Exploits Malicious Ads to Spread CastleStealer The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WordPress Backups Expose Valuable AWS and Email Credentials
  • Antino Backdoor Utilizes Microsoft 365 in Espionage
  • OpenClaw Unveils Free AI Agent Management Platform
  • Critical GitLab AI Gateway Vulnerability Patched
  • Critical cPanel/WHM Flaws Risk Server Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WordPress Backups Expose Valuable AWS and Email Credentials
  • Antino Backdoor Utilizes Microsoft 365 in Espionage
  • OpenClaw Unveils Free AI Agent Management Platform
  • Critical GitLab AI Gateway Vulnerability Patched
  • Critical cPanel/WHM Flaws Risk Server Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark