Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Executive Summary

A China‑nexus threat actor has launched a new espionage campaign targeting government and policy organizations across Asia, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. The operation deploys a previously undocumented backdoor named Antino, which leverages Microsoft Outlook and OneDrive for command‑and‑control communications. Cisco Talos is monitoring the activity and tracking the associated threat cluster.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-10-02T17:33:16+00:00 - Category: threat-intel

Original Description: Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

"A man is not where he lives but where he loves."

— Unknown
Source: The Hacker News