Published: · Region: Asia · Category: cyber

China‑linked Antino backdoor turns Outlook and OneDrive into covert command channels for espionage

A China‑nexus hacking group tracked as UAT‑11587 is using a Rust‑based backdoor dubbed Antino to hijack Microsoft Outlook and OneDrive as command‑and‑control channels in spear‑phishing campaigns across Asia. The technique lets attackers blend into everyday cloud traffic, making cyber‑espionage against governments and policy groups harder to spot.

A China‑linked cyber group is abusing two of the world’s most common productivity tools — Outlook email and OneDrive cloud storage — as hidden command channels to control infected systems at government and policy organizations across Asia. The campaign, attributed to a cluster tracked as UAT‑11587, revolves around a Rust‑based backdoor known as Antino that security researchers say is built for stealthy, long‑term espionage.

According to technical reporting, the attackers use spear‑phishing emails tailored to specific targets to deliver the Antino malware. Once installed, the backdoor doesn’t beacon out to some suspicious, unknown domain. Instead, it uses legitimate Microsoft Outlook and OneDrive infrastructure for command‑and‑control, blending its traffic with routine email synchronization and file access.

For civil servants, diplomats and think‑tank staff who live in Outlook and OneDrive all day, that design choice raises the stakes. The very tools that make remote work and document sharing straightforward can now serve as a conduit for data theft and covert monitoring. Traditional security systems that flag unfamiliar domains or odd network destinations may miss an implant that talks only to approved cloud services.

The group’s targeting profile points to strategic intent rather than smash‑and‑grab crime. Government agencies and policy organizations hold draft legislation, negotiation positions, intelligence reports and internal debates — exactly the sort of material that foreign ministries and security services value. A well‑placed backdoor in a policy shop’s network can yield insight into how a state plans to vote at the UN or what it will accept in a trade deal.

By writing Antino in Rust, the operators gain several advantages. Rust’s memory‑safety features can make some classes of bugs less likely and complicate reverse engineering. Its growing popularity also means malware written in Rust doesn’t stand out as much in code analysis. Combined with the use of mainstream cloud channels, this makes the backdoor harder to detect and harder to dissect.

The operational impact for defenders is uncomfortable. Blocking Outlook or OneDrive outright is not realistic for most ministries or NGOs. That forces security teams to look deeper into behavioral anomalies: unusual file access patterns, odd timing of data transfers, or subtle changes in how a user’s machine interacts with cloud APIs. It also renews pressure on Microsoft and other providers to offer more granular telemetry and security controls for their own platforms.

Strategically, Antino is part of a wider shift in state‑aligned hacking. Rather than standing up easily blacklisted command servers, advanced groups increasingly hide inside trusted services that everyone depends on. The line between enterprise IT and national security shifts when a routine email sync can also be a control signal from a foreign intelligence operator.

The next indicators to watch are whether similar Outlook/OneDrive‑based backdoors are found in other regions, whether Microsoft issues targeted security advisories or product changes in response, and if regional governments publicly attribute the activity or respond with diplomatic pressure on Beijing. For now, the lesson for policymakers is stark: if your work lives in the cloud, so can someone else’s access to it.

Sources