Government and policy organizations across eight Asian countries have been targeted by a previously undocumented backdoor that exploits Microsoft 365 for command-and-control operations, according to a report published by Cisco Talos. The campaign, attributed to a China-nexus threat actor tracked as UAT-11587, has deployed the Antino backdoor against entities in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. Cisco Talos first identified the threat actor in September 2025 during a spear-phishing campaign aimed at Taiwan's academic, think tank, and civil society policy community.

Since that initial detection, the intrusion set has expanded to target 16 entities across the region, with attacks peaking between March and early June 2026. A concentrated wave of activity occurred on June 8 and 9, 2026, hitting dozens of systems tied to government IT infrastructure. The Antino backdoor is a Rust-compiled Windows malware that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading, and persistence. Its command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive rather than relying on a dedicated server. The implant fetches commands from the attacker's Outlook mailbox folder every 10 seconds by searching for messages with the subject prefix "command_req_[session_id]," while using OneDrive for heartbeat signals and file transfer.

"Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence," security researcher Ashley Shen stated in the report. "Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive." The threat actor has been classified as China-nexus with high confidence based on several indicators: zh-CN language and Simplified Chinese metadata in lure documents, UTC+08:00 time zone in spear-phishing message headers, and nearly a dozen distinct Antino builds featuring Cargo registry paths referencing rsproxy.cn, a high-speed domestic mirror service for crates.io serving mainland China. UAT-11587 is assessed to share tactical overlap with Jewelbug, which exhibits similarities with China-aligned clusters known as CL-STA-0049, Earth Alux, Ink Dragon, and REF7707, though Cisco Talos said its investigation failed to establish a connection between the espionage campaign and Jewelbug's financially motivated cryptocurrency fraud operations.

The attack methodology reveals extensive reconnaissance and social engineering sophistication. UAT-11587 spoofed sender identities trusted by intended recipients to bypass SPF and DMARC security checks, ensuring phishing emails reached victims' inboxes. In one technique, the threat actor recreated Gmail's native attachment preview widget inside the email HTML body using four inline PNG images embedded as Base64-encoded MIME parts, with the entire attachment card wrapped in an anchor tag pointing to an attacker-controlled Cloudflare Pages URL. When Gmail users opened the email in a browser, Gmail's renderer displayed the attacker-controlled HTML, producing a fake attachment widget visually indistinguishable from a legitimate preview. The five-stage attack chain begins with an HTA or WSF stager, progresses through a JavaScript downloader and .NET deserialization chain, and culminates in deploying Antino via DLL sideloading using a legitimate Microsoft-signed binary. The lures and observed targets included Taiwanese political, legislative, civil defense, and policy research subjects, together with regional government, maritime, diplomatic, and security themes—a collection focus consistent with China-nexus actor interests.

The campaign's reliance on Microsoft 365's native services for command-and-control presents detection challenges, as the backdoor abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components. This approach complicates behavioral attribution to the original implant, though it doesn't eliminate observable PowerShell, file-creation, or Registry telemetry, according to the report. The targeting pattern—focusing on foreign affairs, international security, and government policy audiences—aligns with traditional Chinese state-sponsored espionage priorities across the Asia-Pacific region. Organizations in these sectors face an adversary willing to invest in extensive reconnaissance and sophisticated social engineering to tailor lures that maximize the likelihood of compromise. The shift toward abuse of trusted cloud platforms rather than traditional infrastructure signals an evolution in adversary tradecraft designed to blend malicious activity with legitimate enterprise traffic and evade network-based detection.