China-Linked APT Deploys New Antino Backdoor in Asian Govt Attacks
A newly discovered backdoor named Antino is being used in espionage campaigns targeting government entities across Asia. The malware leverages Microsoft cloud services for command and control.
TL;DR
- China-nexus threat group targets government and policy organizations in multiple Asian countries.
- Antino backdoor uses Outlook and OneDrive for C2 communications to avoid detection.
- Targets include Taiwan, India, Philippines, Cambodia, Pakistan, Thailand, and Myanmar.
- Cisco Talos has identified and tracked this previously unknown malware family.
- Organizations should monitor for unusual Microsoft cloud service usage patterns.
A sophisticated cyberespionage operation has been uncovered targeting government and policy institutions throughout Asia. Security researchers at Cisco Talos have identified a novel backdoor, dubbed Antino, that is being deployed by a China-nexus advanced persistent threat (APT) group.
This malware stands out due to its innovative use of legitimate Microsoft cloud services—specifically Outlook and OneDrive—as command and control (C2) channels. By leveraging trusted platforms, attackers can evade traditional network defenses and remain undetected while conducting long-term surveillance operations.
Technical Characteristics of Antino Backdoor
- Antino is a previously unreported backdoor specifically designed for stealthy data exfiltration and remote access.
- The malware communicates with attacker-controlled infrastructure through Microsoft's Outlook and OneDrive APIs.
- It avoids direct network connections that could trigger firewall alerts by masquerading traffic within normal business cloud activity.
- Initial infection vectors appear to involve spear-phishing emails tailored to each targeted organization.
- The backdoor includes functionality for file transfer, system reconnaissance, and persistent access maintenance.
Operational Impact and Defensive Recommendations
- Multiple government agencies across eight Asian nations have been compromised as part of this campaign.
- Attackers maintain long dwell times, suggesting extensive intelligence collection rather than disruptive goals.
- Organizations should implement enhanced monitoring for anomalous Microsoft cloud service authentication patterns.
- Security teams should review email gateway logs for suspicious attachments or links sent to high-value personnel.
- Multi-factor authentication and privileged access management can limit lateral movement if initial access is gained.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.