China-Linked Group Uses Microsoft 365 as Command Channel for Sophisticated Backdoor Tool
Cisco Talos has identified a China-linked group called UAT-11587 that has been using a sophisticated backdoor tool called Antino to spy on Asian governments. The group, tracked since September 2025, has targeted at least 16 government and policy organizations across eight countries.
The Antino backdoor is written in Rust and allows the attackers to communicate through Microsoft Graph, hiding their traffic among normal Microsoft 365 activity. This makes it difficult for security systems to detect the malicious communication.
The attack starts with a phishing email that tricks victims into downloading an HTA file, which ultimately sideloads Antino onto the disk. The backdoor then checks its Outlook mailbox for new commands every ten seconds, sending stolen files to OneDrive and receiving attacker tools in return.