A recently uncovered backdoor named Antino has been exploiting Microsoft 365 services for its command and control operations, posing a significant threat to high-profile sectors. This sophisticated malware utilizes Outlook and OneDrive to discreetly issue commands, exfiltrate data, and maintain access to compromised systems. The campaign, identified as UAT-11587 by Cisco Talos researchers, began in September 2025 and has primarily targeted government, defense, diplomatic, academic, and policy institutions across eight countries, including Taiwan, India, and the Philippines. By July 2026, approximately 350 endpoints were compromised, highlighting the extensive reach of this operation.
The attackers employed tailored phishing tactics, leveraging trusted cloud services to bypass traditional email defenses. Antino's architecture is built using Rust and operates through Microsoft Graph, enabling communication without exposing a command server. The malware checks for instructions every 10 seconds via an Outlook mailbox, with OneDrive used for status updates and file transfers.
The campaign's strategic approach to using familiar platforms for malicious activities emphasizes the need for enhanced vigilance. The malware's deployment involved sophisticated techniques like DLL sideloading and Windows troubleshooting component abuse, which help it evade detection. Despite these efforts, Talos provides detection signatures and network rules to assist defenders in identifying and mitigating the threat.
The deceptive nature of the phishing emails was notable, as they mimicked trusted organizations and email attachment previews to lure victims. Although DMARC policies detected some inconsistencies, the lack of enforcement allowed delivery, underscoring the importance of strict email authentication measures. While Talos linked the campaign to China with high confidence, further connections to other threat groups remain unconfirmed.

