Threats · 2h ago

Talos Maps Antino to Microsoft 365 Control

Cisco Talos says the China-linked cluster UAT-11587 targeted government and policy organizations across Asia and, by July 2026, had touched at least 16 institutional environments in eight countries. The activity includes a previously undocumented Rust Windows backdoor Talos calls Antino.

Antino does not call out to a separate attacker server. It uses Microsoft Graph to hide its commands inside Outlook and OneDrive activity, so its control traffic looks like ordinary Microsoft 365 use unless defenders are inspecting the right account and object changes.

That matters most for organizations that rely on Microsoft 365 for mail and file sharing: the cloud tenant itself becomes part of the attack surface, and network monitoring alone may not expose the command channel. The reporting also leaves one judgment unresolved — how much of the regional activity is one coherent operation versus overlapping access by related actors.

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-09-30

Editions

Related stories