China-Linked Hackers Deploy Sophisticated Backdoor Using Microsoft 365 Services
A sophisticated hacking campaign attributed to China has been uncovered by Cisco Talos researchers. The threat actor, known as UAT-11587, has compromised at least 16 government and policy organizations across eight Asian countries since September 2025.
The hackers deployed a novel Rust-based backdoor called Antino that uses Microsoft 365 services for covert communications. Antino communicates exclusively through Microsoft Outlook and OneDrive, eliminating the need for a traditional command-and-control server.
According to Cisco Talos researcher Ashley Shen, Antino supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading, and persistence.
The campaign has targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. The hackers used spear-phishing emails with fake Gmail attachment previews to gain initial access, followed by a series of stages that led to the deployment of Antino.