A new China-nexus campaign uses a backdoor called Antino to target government and policy groups across Asia. It hides in Outlook and OneDrive—making it tough to spot.
Government and policy organizations across Asia are under attack. A new campaign, run by a China-nexus threat actor, is using a previously undocumented backdoor called Antino. And here's the twist: it's hiding in plain sight inside tools you probably use every day—Outlook and OneDrive.
Cisco Talos is tracking this cluster. They've seen it hit government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. If you work in or with any of these sectors, this one deserves your attention.
### Why This Backdoor Is Different
Antino isn't your typical smash-and-grab malware. It's patient. It uses Outlook for command-and-control (C2) and OneDrive for data exfiltration. That means the traffic looks normal. It blends into the noise of everyday business communications.
Think about it. How often does your team send emails or sync files to the cloud? Constantly. So when an attacker uses those same channels, traditional security tools often miss it. It's like a burglar who walks in through the front door wearing a delivery uniform.
### The Targets and What's at Stake
The campaign has zeroed in on:
- Government agencies
- Policy organizations
- Diplomatic and strategic think tanks
These aren't random targets. They're chosen for the sensitive information they hold—policy drafts, internal communications, strategic plans. The kind of data that can influence decisions at the highest levels.
### How Antino Operates
From what researchers can tell, Antino establishes persistence, then quietly waits. It uses Outlook to receive instructions from its operators. Those instructions might look like ordinary emails. Then it uses OneDrive to upload stolen files. No suspicious domains. No weird IP addresses. Just Microsoft services doing what they normally do.
That's what makes it so hard to catch. Your security stack might flag a connection to a known malicious server, but it won't flag Outlook talking to Microsoft's servers. Because that's normal.
### What This Means for Your Organization
If you're in a targeted region or sector, you can't rely on perimeter defenses alone. You need to monitor behavior, not just signatures. Look for unusual Outlook activity—emails with no subject, strange senders, or odd attachment patterns. Check OneDrive for unexpected file uploads, especially from accounts that don't normally share data.
And train your people. Phishing remains the most common entry point. A single click can let Antino in.
### The Bigger Picture
This isn't the first time attackers have abused legitimate cloud services. It's a growing trend because it works. As defenders get better at spotting malicious infrastructure, attackers pivot to trusted platforms. It's an arms race, and right now, they have the element of surprise.
The good news? Awareness is your first line of defense. Share this with your security team. Review your cloud monitoring. And don't assume that because it's Microsoft, it's safe.
Stay sharp out there.