Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Summary
A China-nexus threat actor is conducting an espionage campaign targeting government and policy organizations across Asia, including Taiwan, India, and the Philippines. The campaign deploys a previously undocumented backdoor named Antino, which utilizes Outlook and OneDrive for command and control communication.
IFF Assessment
The discovery of a new backdoor and an active espionage campaign by a nation-state-linked actor represents a significant threat to targeted organizations and data security.
Defender Context
Defenders should be aware of this emerging threat targeting governmental and policy organizations in Asia. Monitoring network traffic for unusual connections to Outlook and OneDrive services, especially from suspicious sources, could help detect this backdoor. It also highlights the ongoing threat of sophisticated espionage campaigns originating from China-nexus actors.