[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:antino-backdoor-uses-outlook-and-onedrive-for-c2-in-china-nexus-espionage-campai-mutno7le":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":13,"article_ids":14,"ioc_summary":16,"source_urls":17,"status":19,"expires_at":20,"created_at":21,"updated_at":22,"articles":23},"f5f909f2-98b4-441e-9111-3e0ccde67ff9","Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign","antino-backdoor-uses-outlook-and-onedrive-for-c2-in-china-nexus-espionage-campai-mutno7le","China-nexus group UAT-11587 is deploying Antino, a Rust-compiled backdoor that abuses Outlook and OneDrive for C2 communications. Government and policy organizations across eight Asian countries are being targeted in an active espionage campaign since September 2025. The use of legitimate Microsoft 365 services for command and control will evade standard network detection.","high","advisory",[],[],"Hunt for Outlook and OneDrive API calls with suspicious patterns: unusual attachment exfiltration, calendar\u002Fcontact access for data staging, and OneDrive sync to external accounts. Cross-reference with endpoint telemetry for Rust-based process execution and suspicious Microsoft Graph API tokens.",[15],"5511d57e-9721-44fa-afaa-836429b762f6",null,[18],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fantino-backdoor-uses-outlook-and.html","active","2026-10-06T10:05:53.072+00:00","2026-10-04T10:06:00.258195+00:00","2026-10-04T10:06:25.586694+00:00",[24],{"id":15,"title":6,"url":18}]