Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The Antino Backdoor: A China-Linked Espionage Tool Exploiting Microsoft 365




The Antino backdoor is a China-linked tool that has been used to spy on Asian governments using Microsoft 365 as a cover. This article provides a detailed explanation of the Antino backdoor, its capabilities, and the methods used by the attackers to exploit it. The victim list reads like a checklist of what an intelligence service would actually want, and the attribution case is based on accumulated small details rather than any single smoking gun. The Antino backdoor is a significant threat to national security and highlights the need for improved cybersecurity measures.

  • The Antino backdoor is a sophisticated tool linked to China that has been used to spy on Asian governments using Microsoft 365 as a cover.
  • The backdoor has capabilities such as host reconnaissance, shell and PowerShell execution, file transfer, and persistence.
  • The attackers use a convincing phishing email, spoofing techniques, and malicious code injection to exploit the backdoor.
  • The attribution case is based on accumulated small details, including language tags and tooling choices.
  • The victim list includes government agencies, defense ministries, and civil society groups across eight countries.
  • The Antino backdoor is a significant threat to national security and highlights the need for improved cybersecurity measures.



  • The cybersecurity landscape continues to evolve with new threats emerging on a daily basis. One such threat that has recently come to light is the Antino backdoor, a sophisticated tool linked to China that has been used to spy on Asian governments using Microsoft 365 as a cover. In this article, we will delve into the details of the Antino backdoor, its capabilities, and the methods used by the attackers to exploit it.

    The Antino backdoor is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading, and persistence. It operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive. This allows the attackers to blend in with normal Microsoft 365 activity, making it challenging to detect.

    The attack typically starts with a convincing phishing email, which is highly targeted and researched to make it appear credible. The attackers create fake documents that closely resemble real documents, such as a fake workshop document about Taiwan's information warfare or a document that closely copies a real Taiwan Ministry of Finance ruling about tax treatment for legislators. The email spoofing technique used by the attackers takes advantage of a gap many people overlook, where the real sending domain is authorized, but the impersonated domain has a DMARC policy set to monitoring rather than rejection.

    Once the email is opened, a five-stage chain kicks in, leaning on legitimate-looking HTA files, Windows Script Host, and a scripted .NET deserialization trick that abuses a known gadget chain to load malicious code inside a trusted process. The final stage sideloads Antino through a signed Microsoft diagnostic binary, meaning the thing dropping the backdoor onto disk is a tool Windows itself trusts by default. Cloudflare Pages, R2, and Amazon CloudFront carried almost every stage of this, which kept the traffic blending into ordinary HTTPS the whole way through.

    Once Antino is running, it checks its Outlook mailbox for new commands every ten seconds. The commands and results are sent as structured JSON hidden inside specially formatted email subjects. A separate system is used to upload stolen files to one OneDrive folder and download attacker tools from another.

    The attribution case leans on accumulated small details rather than any single smoking gun. Decoy document metadata carries Simplified Chinese language tags and a UTC+8 timestamp, a combination more consistent with mainland China than Taiwan or Hong Kong, where Traditional Chinese dominates. Separately, ten different Antino builds reference a Rust package mirror built specifically to speed up dependency downloads inside mainland China, the kind of tooling choice a developer picks for convenience, not for disguise.

    The victim list reads like a checklist of what an intelligence service would actually want: defense ministries, legislatures, foreign affairs offices, border and interior security agencies, plus the think tanks and civil society groups that tend to know things governments care about early. Around 350 compromised endpoints turned up across eight countries, with the largest single wave, roughly 57 new endpoints, hitting India over two days in June. That's not noise. That's a deliberate and sustained collection effort.

    In conclusion, the Antino backdoor is a sophisticated tool that has been used by a China-linked group to spy on Asian governments using Microsoft 365 as a cover. The attackers used a combination of phishing, email spoofing, and malicious code injection to exploit the backdoor. The attribution case is based on accumulated small details rather than any single smoking gun. The victim list reads like a checklist of what an intelligence service would actually want. The Antino backdoor is a significant threat to national security and highlights the need for improved cybersecurity measures.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-Antino-Backdoor-A-China-Linked-Espionage-Tool-Exploiting-Microsoft-365-ehn.shtml

  • https://securityaffairs.com/200264/apt/antino-backdoor-uses-your-inbox-as-its-control-panel.html


  • Published: Sat Oct 3 06:17:22 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us