A New Backdoor Hides in Microsoft 365 Traffic
About 350 computers in government and policy organizations across Asia have been infected with a new backdoor called Antino.
A China-linked cluster named UAT-11587 used Outlook and OneDrive as its command channel. In this way, it disguised malicious traffic as ordinary Microsoft 365 activity.
Scope of the Campaign
Cisco Talos has watched the campaign since at least September 2025. The attacks hit organizations in eight countries, including Taiwan, India, the Philippines, Pakistan, and Thailand.
Targets included defense and diplomatic agencies, parliaments, and border services. Universities and think tanks were also hit.
How the Infection Unfolds
In one chain, the attack began with a phishing email. The victim was redirected through Cloudflare Pages. Then the infection passed through several stages. Finally, it loaded Antino through DLL sideloading.
What Antino Can Do
Antino is written in Rust and runs on Windows. The backdoor collects details about the computer and runs commands. It also transfers files and executes code in memory.
Microsoft Graph as a Command Channel
To talk with its operators, the malware uses Microsoft Graph. Outlook receives the commands. Meanwhile, OneDrive serves to exchange files and data about the infected system.
Attribution to a China-Linked Cluster
Talos links the campaign to a China-nexus threat cluster with high confidence. However, it does not name a specific state agency.
Several clues point to China. They include metadata in Simplified Chinese and the UTC+8 time zone. In addition, the infrastructure in use and the choice of targets fit that picture.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.