$ techbeacon▋
Malware

China-linked Threat Actor Exploits Outlook and OneDrive in New Asian Government Espionage Campaign

China-linked Threat Actor Exploits Outlook and OneDrive in New Asian Government Espionage Campaign

Security researchers have identified a fresh cyber‑espionage operation that leverages Microsoft Outlook and OneDrive as covert command‑and‑control channels. The campaign, which appears to be orchestrated by a threat group with ties to China, has been observed targeting government and policy institutions across a swath of Asian nations, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand and Myanmar.

The intrusion method relies on a custom backdoor dubbed “Antino,” which embeds malicious payloads within seemingly innocuous Outlook emails and synchronises data through OneDrive accounts. By using these widely trusted cloud services, the actors can blend their traffic with legitimate corporate communications, making detection by conventional network monitoring tools more difficult.

Analysts say the choice of Outlook and OneDrive reflects a broader trend among sophisticated actors to exploit legitimate SaaS platforms for stealth. Once a victim’s machine is compromised, the backdoor contacts the attacker’s infrastructure through encrypted Outlook messages or hidden OneDrive files, receiving further instructions or exfiltrating data without raising immediate alarms.

The affected organizations span ministries, regulatory bodies and policy think‑tanks, suggesting the campaign’s primary aim is to harvest diplomatic correspondence, strategic policy drafts and internal deliberations. While the exact volume of data accessed remains unclear, the breadth of the target list points to a coordinated effort to build a regional intelligence picture.

Microsoft has not publicly confirmed involvement in the specific incidents, but its security teams have previously warned about the misuse of Office 365 services for malicious purposes. The researchers who uncovered the operation recommend that entities tighten email filtering, enforce multi‑factor authentication on cloud accounts, and monitor for anomalous file‑sharing activity within OneDrive.

Attribution to a China‑nexus group is based on observed tooling, code reuse, and infrastructure overlaps with earlier campaigns linked to state‑aligned actors. However, definitive attribution remains challenging due to the use of compromised legitimate services that can obscure the true origin of the traffic.

Experts caution that the campaign underscores the need for continuous threat‑hunting and robust incident‑response capabilities, especially for government bodies handling sensitive policy information. As more organizations adopt cloud‑based productivity suites, the line between legitimate collaboration and covert espionage is likely to blur further, prompting a reassessment of security baselines across the public sector.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related