Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Cisco Talos says China-nexus UAT-11587 deployed the Antino backdoor against Asian government and policy organizations.
Cisco Talos says China-nexus cluster UAT-11587 deployed a previously undocumented Rust Windows backdoor, Antino, against government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and later Syria. Antino uses Microsoft Graph with Outlook and OneDrive as dead-drop command and control and supports reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode, and persistence. Access begins with spear-phishing that spoofs trusted senders and a fake Gmail attachment card leading to an HTA or WSF stager, then DLL sideloading via GatherOsState.exe. Talos notes overlap with Jewelbug and related clusters but tracks this activity separately.