China-Linked Spies Hide Inside Outlook and OneDrive to Steal Asian Government Secrets
A newly documented backdoor called Antino is sitting on at least 16 government networks across eight Asian countries, and it talks to its handlers through legitimate Microsoft 365 traffic.

Key points
- Cisco Talos has identified at least 16 government and policy institutions targeted across eight Asian countries by July 2026, in a campaign it first spotted in September 2025.
- The hackers, tracked as UAT-11587, use a new Windows backdoor called Antino that hides its communications inside normal-looking Microsoft Outlook and OneDrive traffic.
- Talos assesses with high confidence that the group is working on behalf of China, based on development and targeting clues.
- Victim countries include Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand and Myanmar.
- The attack starts with a spear-phishing email, meaning a fake message aimed at a specific person, and runs through a five-stage installer before the backdoor lands.
A suspected Chinese spying group has spent the past ten months quietly breaking into government offices across Asia, and the tool it uses to steal files is designed to look like someone checking their work email.
Cisco Talos, the threat research arm of Cisco, published its findings on the campaign and is tracking the hackers as UAT-11587. Talos first saw the activity in September 2025. By July 2026, its researchers had counted at least 16 affected or targeted institutions in eight Asian countries, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand and Myanmar.
The backdoor itself is new. Talos calls it Antino, a name pulled from leftover notes in the attackers' own code. It is written in Rust, a modern programming language, and runs on Windows.
What does the backdoor actually do?
Once installed, Antino gives the attackers full run of the machine. It can map out the computer and the network it sits on, run commands and PowerShell scripts (PowerShell is a built-in Windows tool for automating tasks), move files in and out, load extra attack code directly into memory so nothing suspicious hits the hard drive, and keep itself running after a reboot.
That is a standard spy kit. What makes Antino worth paying attention to is how it phones home.
How does it hide from defenders?
Antino does not use a shady server somewhere on the open internet. It uses Microsoft 365. The backdoor talks to its operators through Microsoft Graph, the official programming interface for Microsoft's cloud, by reading and writing items inside Outlook mailboxes and OneDrive folders.
To a firewall or a security product, that traffic looks like an employee checking their email. Blocking it outright would break the office. This is why state-backed groups keep gravitating to it.
The delivery route is more familiar. The hackers send tailored spear-phishing emails with decoy documents matched to the target's job, then run the victim through a five-stage infection chain before Antino is dropped. Much of the staging and tracking infrastructure sits behind Cloudflare, which further hides where the attackers really are.
Who is behind it?
Talos assesses with high confidence that UAT-11587 is a China-nexus group, based on how the malware was built, the setup of the development environment, and the choice of targets. The victim list, government ministries and policy bodies in countries that sit on China's diplomatic fault lines, lines up with that read.
The campaign was first reported by The Hacker News.
| Detail | What Talos found |
|---|---|
| Group | UAT-11587 (China-nexus, high confidence) |
| Backdoor | Antino, Rust-compiled, Windows |
| First seen | September 2025 |
| Scope by July 2026 | 16+ institutions, 8 countries |
| Command channel | Microsoft Graph via Outlook and OneDrive |
| Delivery | Spear-phishing, 5-stage chain, Cloudflare staging |
One reporter's read: the interesting part here is not Antino's feature list, which is unremarkable, but the continued drift of state-backed operators into cloud services their victims cannot block. If your detection strategy still assumes command-and-control traffic goes to a sketchy IP address, campaigns like this one will keep walking past it. Watch the Graph API logs, not the firewall.



