⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

October 2, 2026

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign Ravie LakshmananOct 02, 2026Cyber Espionage / Malware Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster under the moniker UAT-11587. The threat actor was first detected in September 2025 in connection with a spear-phishing campaign directed against Taiwan's academic, think tank, and civil society policy community. Since then, attacks linked to the intrusion set have expanded to target 16 entities across eight…