Ethical Hacking News
A new wave of cyber espionage has swept across Asia, targeting government and policy organizations in multiple countries, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. The campaign, attributed to a China-nexus threat actor, has employed a previously undocumented backdoor codenamed Antino to execute a series of sophisticated attacks. The Antino backdoor, a Rust-compiled Windows tool, was first detected in September 2025 in connection with a spear-phishing campaign directed against Taiwan's academic, think tank, and civil society policy community. The threat actor, identified as a China-nexus entity, has been assessed to share some level of overlap with Jewelbug, a China-based hackers-for-hire group characterized as a threat actor that carries out espionage operations and a for-profit cryptocurrency fraud business. The campaign's use of Microsoft 365 and OneDrive as C2 channels, and its sophisticated social engineering tactics, demonstrate a high level of expertise and sophistication. The threat actor's TTPs have been analyzed, revealing a propensity to target audiences interested in foreign affairs, international security, and government policy.
A new wave of cyber espionage has swept across Asia, targeting government and policy organizations in multiple countries. The campaign employs a previously undocumented backdoor codenamed Antino to execute sophisticated attacks. The Antino backdoor uses Microsoft 365 and OneDrive as native command-and-control channels. The threat actor has been linked to a China-nexus entity, with some overlap with Jewelbug, a China-based hackers-for-hire group. The campaign targets audiences interested in foreign affairs, international security, and government policy. The backdoor supports host reconnaissance, command execution, and persistence, and can list running processes and execute PowerShell scripts. The threat actor uses social engineering techniques, such as spoofing sender identities and employing a five-stage attack process.
A new wave of cyber espionage has swept across Asia, targeting government and policy organizations in multiple countries, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. The campaign, attributed to a China-nexus threat actor, has employed a previously undocumented backdoor codenamed Antino to execute a series of sophisticated attacks.
The Antino backdoor, a Rust-compiled Windows tool, was first detected in September 2025 in connection with a spear-phishing campaign directed against Taiwan's academic, think tank, and civil society policy community. Since then, attacks linked to the intrusion set have expanded to target 16 entities across eight Asian countries. The backdoor's native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.
The threat actor, identified as a China-nexus entity, has been assessed to share some level of overlap with Jewelbug, a China-based hackers-for-hire group characterized as a threat actor that carries out espionage operations and a for-profit cryptocurrency fraud business. However, Cisco Talos, the organization tracking the cluster, has failed to establish a connection between the espionage campaign and Jewelbug's financially motivated activity, prompting it to designate UAT-11587 as a separate activity set.
The China-nexus threat actor's tactics, tactics, and procedures (TTPs) have been analyzed, revealing a propensity to target audiences interested in foreign affairs, international security, and government policy. The attack chain itself is a five-stage process that begins with a HTA or WSF stager and culminates in the deployment of Antino. The Cloudflare URL in the phishing email leads to the download of an HTA or WSF file that's then executed to retrieve a JavaScript downloader and decryptor.
The Antino backdoor, when deployed, communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, instead of depending on a conspicuous dedicated command-and-control (C2) server. The backdoor supports host reconnaissance, command execution, and persistence, and can also list running processes, enumerate directories, run PowerShell scripts, shellcode, operator-supplied programs, and commands using "cmd.exe".
The China-nexus threat actor's use of Microsoft 365 and OneDrive as C2 channels has been noted, with the backdoor fetching commands from the threat actor's Outlook mailbox folder every 10 seconds by looking for messages with the subject prefix "command_req_[session_id]". This behavior suggests that the actor has conducted extensive reconnaissance of the target organizations in order to tailor the content and maximize the chance of success.
The campaign's lure theme and targeting provide additional contextual support, with the adversary's lures and observed targets including Taiwanese political, legislative, civil defense, and policy research subjects, together with regional government, maritime, diplomatic, and security themes. The attack chain itself is a five-stage process that begins with a HTA or WSF stager and culminates in the deployment of Antino.
The China-nexus threat actor's use of social engineering techniques, such as spoofing sender identities trusted by the intended recipients to bypass SPF and DMARC security checks, and the closely replicated reconstruction of Gmail's native attachment preview widget inside the email HTML body, demonstrates a sophisticated level of expertise. The actor has also employed a five-stage process to execute the attack, which begins with a HTA or WSF stager and culminates in the deployment of Antino.
In conclusion, the China-nexus cyber espionage campaign utilizing Antino backdoor has been identified, with the threat actor targeting government and policy organizations in multiple Asian countries. The campaign's use of Microsoft 365 and OneDrive as C2 channels, and its sophisticated social engineering tactics, demonstrate a high level of expertise and sophistication. The threat actor's TTPs have been analyzed, revealing a propensity to target audiences interested in foreign affairs, international security, and government policy.
Related Information:
https://www.ethicalhackingnews.com/articles/A-China-Nexus-Cyber-Espionage-Campaign-Utilizing-Antino-Backdoor-for-APT-Style-Attacks-ehn.shtml
https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html
Published: Fri Oct 2 13:05:42 2026 by llama3.2 3B Q4_K_M