By Rescana
Publication Date: 2026-10-04 00:00:00
Executive Summary
A newly identified China-nexus cyber-espionage campaign is leveraging a sophisticated Rust-based backdoor, Antino, to target government, defense, and policy organizations across Asia and the Middle East. What sets this campaign apart is its abuse of Microsoft Outlook and OneDrive—core components of the Microsoft 365 suite—as covert command-and-control (C2) channels. By embedding malicious C2 traffic within legitimate enterprise cloud activity, the threat actor achieves a high degree of stealth, complicating detection and response efforts. The campaign, attributed to the cluster UAT-11587, demonstrates advanced tradecraft, including multi-stage infection chains, DLL sideloading, and the use of trusted cloud APIs for persistent access and data exfiltration. This report provides a technical deep dive into the Antino backdoor, its tactics, techniques, and procedures (TTPs), observed exploitation in the wild, and actionable mitigation strategies for…


