malware
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Medium
Summary
A China-nexus threat actor, tracked as UAT-11587, has been targeting government and policy organizations across Asia, including Taiwan, India, and the Philippines, with a new campaign utilizing the Antino backdoor. The campaign leverages Microsoft 365 (Outlook and OneDrive) for command and control, bypassing traditional C2 servers. The campaign began in September 2025 and has expanded to include targets in Syria, utilizing a five-stage attack chain.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
