$ techbeacon▋
CVE & Exploits

China-Linked Espionage Group Exploits Microsoft 365 via Antino Backdoor, Cisco Talos Reports

China-Linked Espionage Group Exploits Microsoft 365 via Antino Backdoor, Cisco Talos Reports

Cisco Talos has identified a persistent espionage campaign, dubbed UAT-11587, that leverages a malicious component known as the Antino backdoor to turn Microsoft 365 services into a covert command-and-control (C2) channel. The operation, which the security firm traces back to a China‑affiliated threat actor, has been active since at least September 2025 and continued to compromise targets through July 2026.

The investigators say the group embeds the Antino payload within legitimate‑looking Office 365 files, allowing it to blend in with normal cloud traffic. Once a victim opens the compromised document, the backdoor establishes an encrypted link to Microsoft 365 infrastructure, using the platform’s own APIs to download additional tools and exfiltrate data without triggering typical network‑based alarms.

According to Talos, the primary victims are governmental bodies across several Asian nations. By operating within the trusted Microsoft 365 environment, the attackers can bypass many traditional perimeter defenses and remain hidden from security teams that focus on external traffic. The campaign’s sophistication suggests a high level of resources and an intimate understanding of both the cloud service’s architecture and the operational security practices of targeted agencies.

Microsoft has not publicly commented on the specific incidents, but the company routinely updates its threat‑model guidance for Office 365 users. Security experts recommend organizations enforce strict macro policies, monitor anomalous API calls, and employ multi‑factor authentication to reduce the risk of credential theft that could enable such backdoor communications.

Talos’ disclosure highlights a broader trend of threat actors repurposing widely adopted SaaS platforms for illicit ends. As more enterprises and governments migrate critical workflows to cloud services, the attack surface expands, prompting a shift from classic malware delivery to “living off the land” techniques that exploit trusted infrastructure. Analysts expect that future investigations will uncover additional campaigns using similar methods, underscoring the need for continuous monitoring and rapid response capabilities within cloud environments.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related