China-Nexus Espionage Campaign Leverages Antino Backdoor via Outlook and OneDrive for C2
A China-nexus threat group employs the Antino backdoor, leveraging Microsoft 365 services like Outlook and OneDrive for command-and-control (C2) in a targeted espionage campaign. The campaign, tracked as UAT-11587, targets government and policy organizations across Asia and Syria, utilizing sophisticated social engineering and code-signing techniques to evade detection.
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor.
The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
*** END OF TRANSMISSION ***