China-Nexus Cyber-Espionage Campaign Exploits Outlook and OneDrive for Stealthy Attacks
A sophisticated China-nexus cyber-espionage campaign has been detected targeting government, defense, and policy organizations across Asia and the Middle East.
The threat actor, attributed to cluster UAT-11587, is leveraging a Rust-based backdoor called Antino, which exploits Microsoft Outlook and OneDrive as covert command-and-control channels.
The campaign's tactics, techniques, and procedures (TTPs) demonstrate advanced tradecraft, including multi-stage infection chains, DLL sideloading, and the use of trusted cloud APIs for persistent access and data exfiltration.