hacker-news · Crawled Oct 2, 2026

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

4 IoCs 3 Actors
Read original article ↗

AI Summary

A China-nexus threat actor tracked as UAT-11587 has been conducting a cyber espionage campaign since September 2025, targeting government and policy organizations across Asia and Syria. The campaign uses a previously undocumented Rust-compiled Windows backdoor named Antino, which leverages Microsoft 365 services—specifically Outlook and OneDrive—for command-and-control (C2) communications. Initial access is achieved via spear-phishing emails with spoofed sender identities and a fake Gmail attachment preview widget, leading to a multi-stage infection chain culminating in the deployment of the Antino backdoor using DLL sideloading.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 4 extracted

Type Value Detail
Domain rsproxy[.]cn Details →
Filename slc.dll Details →
Filename TestAssembly.dll Details →
Filename GatherOsState.exe Details →

MITRE ATT&CK TTPs 21 techniques