news.mlab.sh
Back to the feed
malware

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Medium
Image: The Hacker News
Summary

A China-nexus threat actor, tracked as UAT-11587, has been targeting government and policy organizations across Asia, including Taiwan, India, and the Philippines, with a new campaign utilizing the Antino backdoor. The campaign leverages Microsoft 365 (Outlook and OneDrive) for command and control, bypassing traditional C2 servers. The campaign began in September 2025 and has expanded to include targets in Syria, utilizing a five-stage attack chain.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Also covered by 2 other source(s)

Report an error
Confirmed errors are fixed and listed on /corrections.