MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-02 · via The Hacker News

New Antino Malware Leverages Microsoft Cloud Services for Covert Communications in Asian Espionage Operations

Image via The Hacker News
Image via The Hacker News

A previously unknown backdoor named Antino has been deployed in a targeted campaign against government and policy organizations across multiple Asian nations including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. The malware exploits Outlook and OneDrive as command-and-control communication channels, enabling sophisticated evasion of traditional network monitoring. Cisco Talos researchers are tracking the activity and attribute it to a threat actor with connections to China.

Expanded Detail

The discovery of Antino represents a notable development in state-sponsored cyber operations targeting the Asia-Pacific region. By weaponizing legitimate cloud services rather than relying on traditional infrastructure, the threat actors behind this campaign have developed a method to blend malicious communications within normal business traffic, complicating detection efforts for security teams relying on conventional network analysis tools.

This approach highlights an evolving challenge in cybersecurity: the dual-use nature of mainstream enterprise platforms. As organizations increasingly depend on cloud services for legitimate operations, distinguishing between benign and malicious activity becomes considerably more difficult, particularly when adversaries demonstrate sophistication in operational security practices.

Context

The targeting of government and policy institutions across multiple nations could undermine regional stability and institutional confidence in digital security. Organizations in affected countries may face increased pressure to strengthen defensive capabilities and review cloud service usage policies. The incident may also prompt broader discussions among international partners regarding attribution and coordinated responses to state-sponsored cyber activity, potentially affecting how nations approach digital diplomacy and cybersecurity partnerships.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
Resilient WordPress Malware Employs Self-Replication Across Multiple System Layers to Survive Cleanup · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign.” Browse more stories.