LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
backdoorhigh

Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel

Cisco Talos researchers have identified a new Rust-based backdoor, dubbed Antino, which a China-linked threat actor known as UAT-11587 is using to conduct espionage against government and policy organizations in Asia. The backdoor uniquely leverages Microsoft 365 services, specifically Outlook and OneDrive, for its command-and-control (C2) communications, allowing its traffic to blend in with…

ZeroDay News ·

Source: Security Affairs

Cisco Talos researchers have identified a new Rust-based backdoor, dubbed Antino, which a China-linked threat actor known as UAT-11587 is using to conduct espionage against government and policy organizations in Asia. The backdoor uniquely leverages Microsoft 365 services, specifically Outlook and OneDrive, for its command-and-control (C2) communications, allowing its traffic to blend in with legitimate network activity.

Since September 2025, Talos has been tracking UAT-11587, observing at least 16 organizations across eight Asian countries targeted by July 2026. The group's toolkit includes Antino, a Windows backdoor compatible with both 32-bit and 64-bit systems. Antino offers standard backdoor functionalities such as host reconnaissance, shell and PowerShell execution, file transfer capabilities, in-memory shellcode loading, and persistence mechanisms.

The distinctive feature of Antino lies in its C2 channel, which operates exclusively through Microsoft Graph. It reads commands from an Outlook mailbox and exfiltrates stolen data to a OneDrive folder. This method helps the malicious traffic evade detection by appearing as normal Microsoft 365 usage.

Initial compromise typically begins with highly targeted phishing emails. UAT-11587 crafts convincing decoy documents, indicating prior research into their victims. Examples include a fake workshop document concerning Taiwan's information warfare and a document that closely mimics a genuine Taiwan Ministry of Finance ruling on tax treatment for legislators. Another observed decoy reused an Associated Press story about alleged Russian offers to the U.S. regarding Venezuela.

The phishing technique employs email spoofing, where emails are sent through a legitimate provider using one domain as the technical sender, while the visible "From" address impersonates the target organization. Although SPF checks pass due to the authorized sending domain, DMARC often fails due to the mismatch. However, if the impersonated domain's DMARC policy is set to monitoring rather than rejection, the emails still reach the inbox.

For Gmail users, attackers recreate Gmail's attachment preview card pixel-by-pixel using embedded HTML images. This fake preview then links to an attacker-controlled page. Since Gmail renders the HTML as received, the fake preview appears indistinguishable from a legitimate one, exploiting user trust rather than a technical vulnerability.

Upon clicking the malicious link, a five-stage infection chain is initiated. This chain involves legitimate-looking HTA files, Windows Script Host, and a scripted .NET deserialization trick that abuses a known gadget chain to load malicious code within a trusted process. The final stage sideloads Antino using a signed Microsoft diagnostic binary, leveraging a tool inherently trusted by Windows. Cloudflare Pages, R2, and Amazon CloudFront are used to host various stages of this attack, further ensuring traffic blends into ordinary HTTPS.

Once active, Antino polls its designated Outlook mailbox every ten seconds for new commands. Commands and results are transmitted as structured JSON data embedded within specially formatted email subjects. Command emails are identified by the prefix "command_req_[session_id]," and response emails by "command_res_[session_id]." A separate system manages file uploads to a specific OneDrive folder for exfiltration and downloads of attacker tools from another.

Attribution to a China-linked group is based on several cumulative details. Decoy document metadata contains Simplified Chinese language tags and UTC+8 timestamps, which are more consistent with mainland China than Taiwan or Hong Kong, where Traditional Chinese is prevalent. Additionally, ten different Antino builds reference a Rust package mirror specifically designed to accelerate dependency downloads within mainland China, suggesting a developer's choice for convenience rather than obfuscation. The victim list, which includes defense ministries, legislatures, foreign affairs offices, border and interior security agencies, and associated think tanks and civil society groups, aligns with typical intelligence gathering objectives.

backdoorespionagemicrosoft 365phishingapt
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.