New "Antino" Backdoor Abuses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
What happened
Cisco Talos has disclosed a previously undocumented backdoor, codenamed Antino, deployed by a China-nexus threat actor in an espionage campaign targeting government and policy organizations across Asia — specifically Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. According to Talos, the malware leverages legitimate Microsoft services — Outlook and OneDrive — as command-and-control (C2) channels, a technique that helps blend malicious traffic in with normal enterprise cloud activity.
Why it matters
Government and policy institutions are high-value espionage targets, and the breadth of countries named suggests a coordinated, multi-country operation rather than an isolated incident. Using trusted Microsoft 365 services for C2 is significant because it lets the actor's traffic ride on domains and protocols that are rarely blocked or deeply inspected, complicating network-based detection and making the activity harder to distinguish from legitimate collaboration-suite usage.
What defenders should watch for
- Review Microsoft Graph API and Outlook/OneDrive application access logs for unusual service principal or application activity, especially from accounts/apps that shouldn't need broad mailbox or file access.
- Hunt for anomalous OAuth app consent grants and new third-party or custom applications registered against Outlook/OneDrive scopes.
- Look for unexpected processes or scripts making calls to Microsoft Graph/OneDrive/Outlook REST endpoints outside of known business applications.
- Flag unusual mailbox rule creation, draft/sent-item manipulation, or file uploads/downloads to OneDrive that don't match user behavior baselines — common tradecraft when webmail/cloud storage is abused as a C2 transport.
- Prioritize monitoring for government, policy, and diplomatic organizations in the named region, and share indicators with sector-specific ISACs where applicable.
At this stage, technical indicators (hashes, infrastructure, specific API abuse patterns) have not been detailed in the initial reporting available to us, so treat the above as general hunting angles pending further technical disclosure from Talos.
Developing story
This is net-new intelligence based on initial reporting and is still developing; attribution, scope, and technical details may be refined as more analysis is published. For the original report, see The Hacker News.