A sophisticated cyber espionage campaign has been uncovered, leveraging a previously unknown backdoor called Antino to compromise Outlook and OneDrive accounts in China. This malicious toolchain is being used by threat actors to gain unauthorized access to sensitive information, marking a significant escalation in the ongoing cat-and-mouse game between state-sponsored attackers and their targets.
At its core, the Antino backdoor is designed to establish command and control (C2) channels using Outlook’s built-in features. Once activated, it allows the attackers to exfiltrate sensitive data from compromised accounts, including emails, documents, and even credentials stored in OneDrive. The use of widely adopted Microsoft services makes this tactic particularly effective, as users often rely on these tools for both personal and professional communication.
The campaign, dubbed “China-Nexus,” appears to be targeting organizations with connections to China, highlighting the ongoing tensions between state-sponsored actors and their global adversaries. By exploiting vulnerabilities in commonly used software, these attackers are able to move undetected through networks, gathering intelligence and building a comprehensive picture of an organization’s internal workings.
One of the most worrying aspects of Antino is its ability to operate covertly, even when basic security measures such as antivirus software are in place. This stealthy behavior allows it to evade detection by traditional threat-hunting methods, making it all the more challenging for organizations to identify and contain these types of attacks. Furthermore, the use of Outlook’s built-in features means that users may not even notice their accounts being compromised until it’s too late.
The implications of this campaign are far-reaching, underscoring the need for organizations to take a holistic approach to cybersecurity. This includes implementing robust email security measures, such as advanced threat protection and regular account monitoring, to mitigate the risk of C2 channel exploitation. Additionally, users should be educated on best practices for managing sensitive data stored in cloud services like OneDrive.
In light of this incident, it’s essential for organizations to reevaluate their security posture and prioritize proactive threat hunting strategies. By staying vigilant and adapting to emerging threats, companies can better protect themselves against the escalating attacks from state-sponsored actors. As always, a robust defense requires a combination of technical expertise and user awareness – in this case, understanding how seemingly innocuous services like Outlook and OneDrive can be used as vectors for malicious activity.
Source: The Hacker News — 2026-10-02