China-Linked Group Uses Antino Backdoor, Outlook and OneDrive for Espionage in Asia
Moyen · The Hacker News ·
En bref
- China-linked actor targets government and policy groups in Asia.
- Antino backdoor deployed for espionage and persistence.
- Outlook and OneDrive abused as C2 channels.
- Cisco Talos and Microsoft tracked the cluster; no CVEs involved.
- Severity rated medium; defenders should harden cloud services.
A threat cluster with suspected ties to China has been conducting espionage operations across Asia, focusing on government agencies and policy-focused organizations in seven different nations. The group's primary tool is a backdoor called Antino, which it installs on compromised systems to maintain persistent access and exfiltrate sensitive data.
Rather than relying on software vulnerabilities, the actor leverages legitimate cloud services for command-and-control. Specifically, it uses Outlook and OneDrive to blend malicious traffic with normal business activity, making detection more difficult. This technique allows the group to evade traditional network defenses that might flag unusual external connections.
The campaign appears to be motivated by intelligence gathering, targeting entities involved in policy and governance. Cisco Talos and Microsoft have been tracking this activity, though no specific CVEs are associated with the intrusion set. The lack of exploited vulnerabilities means patching alone will not stop the attacks.
Because the backdoor and C2 channels operate through trusted services, defenders need to monitor for anomalous behavior within Outlook and OneDrive, such as unusual login locations, mailbox rule changes, or unexpected file uploads. The medium severity rating reflects the targeted nature of the campaign, but the potential for data theft remains significant.
Organizations in the affected regions should review their cloud security configurations and watch for indicators of compromise related to the Antino backdoor. Collaboration with threat intelligence vendors and sharing of telemetry across sectors will be crucial to disrupting this ongoing espionage effort.
À faire maintenant
- Restrict third-party application access to Outlook and OneDrive, allowing only approved integrations.
- Monitor for anomalous mailbox rule creation, forwarding, and unusual OneDrive file activity.
- Deploy endpoint detection and response (EDR) with behavior rules targeting Antino backdoor indicators.
- Enforce conditional access and multi-factor authentication for all cloud service logins.
- Review logs for suspicious C2 patterns, such as regular beaconing to Outlook or OneDrive from unusual IPs.
- Block known malicious domains and IPs from threat intelligence feeds related to this cluster.
- Train users to report phishing and suspicious cloud sharing invitations promptly.
Source originale
Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.