hacker-news · Crawled Oct 2, 2026
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
4 IoCs 3 Actors
Read original article ↗
AI Summary
A China-nexus threat actor tracked as UAT-11587 has been conducting a cyber espionage campaign since September 2025, targeting government and policy organizations across Asia and Syria. The campaign uses a previously undocumented Rust-compiled Windows backdoor named Antino, which leverages Microsoft 365 services—specifically Outlook and OneDrive—for command-and-control (C2) communications. Initial access is achieved via spear-phishing emails with spoofed sender identities and a fake Gmail attachment preview widget, leading to a multi-stage infection chain culminating in the deployment of the Antino backdoor using DLL sideloading.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 4 extracted
MITRE ATT&CK TTPs 21 techniques
T1027 Obfuscated Files or Information · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1071.004 DNS · Command And Control T1080 Taint Shared Content · Lateral Movement T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1105 Ingress Tool Transfer · Command And Control T1114.002 Remote Email Collection · Collection T1124 System Time Discovery · Discovery T1218.001 Compiled HTML File · Defense Evasion T1566 Phishing · Initial Access T1021.001 Remote Desktop Protocol · Lateral Movement T1036 Masquerading · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1055 Process Injection · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1059.003 Windows Command Shell · Execution T1071.001 Web Protocols · Command And Control T1204.002 Malicious File · Execution T1566.001 Spearphishing Attachment · Initial Access