New 'Antino' Backdoor Hides Behind Microsoft 365 in Asia-Wide Espionage Campaign
Researchers at Cisco Talos have uncovered a new cyber espionage campaign targeting government and policy organisations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand and Myanmar. The group, tracked as UAT-11587, was first seen in September 2025 targeting Taiwan's academic and policy community through spear-phishing emails, and has since expanded to at least 16 organisations in eight countries.
The campaign deploys a previously unseen backdoor named Antino, built using the Rust programming language for Windows systems. It allows attackers to scan infected computers, run commands through shell or PowerShell, transfer files, and load malicious code directly into memory. Unusually, Antino communicates with its operators entirely through Microsoft 365 services, using Microsoft Graph to send and receive instructions via Outlook and OneDrive, making its traffic harder to distinguish from legitimate business activity.
Talos assesses with high confidence that the group behind the campaign is linked to China, based on Simplified Chinese language artefacts in documents used to lure victims and time zone data in phishing emails. While some tactics overlap with a known group called Jewelbug, researchers found no direct evidence connecting this espionage activity to Jewelbug's separate, profit-driven cryptocurrency fraud operations, leading them to track UAT-11587 as a distinct threat.