Antino Windows backdoor activity using Microsoft 365 dead drops
Malware Activity
Summary
Hide ▲
Show ▼
Antino is being deployed as a Windows backdoor that gives operators host reconnaissance, command execution, file transfer, and persistence while routing C2 through Microsoft 365 dead drops, increasing stealth against defenders.
Related Happenings
UAT-11587 Antino spear-phishing campaign against government and policy organizations
Campaign
H score22
First: 02.10.2026 20:33
Last: 02.10.2026 20:33
Sources 1
How related:
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor.
About this happening:
A UAT-11587 spear-phishing campaign is expanding across Asia and Syria, delivering the Antino backdoor to government and policy organizations and increasing th...
UAT-11587 Antino spear-phishing campaign against government and policy organizations
CampaignHow related: Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor.
About this happening: A UAT-11587 spear-phishing campaign is expanding across Asia and Syria, delivering the Antino backdoor to government and policy organizations and increasing th...
Star Blizzard fake event-invitation phishing campaign
Campaign
H score29
First: 29.09.2026 20:20
Last: 29.09.2026 20:20
Sources 1
About this happening:
Star Blizzard is using the RedFlick delivery chain in 2026 to push the CosmicPulse backdoor through phishing emails and a password-protected archive that leads...
Star Blizzard fake event-invitation phishing campaign
CampaignAbout this happening: Star Blizzard is using the RedFlick delivery chain in 2026 to push the CosmicPulse backdoor through phishing emails and a password-protected archive that leads...
NeedyMantis long-term access activity
Malware Activity
H score22
First: 28.09.2026 21:35
Last: 28.09.2026 21:35
Sources 1
About this happening:
The NeedyMantis malware family is being used to maintain long-term access in already breached networks, affecting a small number of targeted intrusions across telecomm...
NeedyMantis long-term access activity
Malware ActivityAbout this happening: The NeedyMantis malware family is being used to maintain long-term access in already breached networks, affecting a small number of targeted intrusions across telecomm...
Latest development: 29.09.2026 16:30
Microsoft said NeedyMantis has been active since at least October 2025 and is used against telecommunications providers, universities and government-linked organizations; the malware is deployed after initial access to maintain long-term access, is installed through DLL side-loading with legitimate software such as Poedit, curl, Vim and TightVNC, and Microsoft attributed the activity as emerging from China while noting at least one operator is Storm-3069.
ValleyRAT malicious installer activity
Malware Activity
H score22
First: 02.09.2026 19:41
Last: 02.09.2026 19:41
Sources 1
About this happening:
ValleyRAT installers delivered through bogus software-download websites are compromising Windows endpoints and reaching users seeking popular software. The operation has a...
ValleyRAT malicious installer activity
Malware ActivityAbout this happening: ValleyRAT installers delivered through bogus software-download websites are compromising Windows endpoints and reaching users seeking popular software. The operation has a...
SynkLoader malware distribution via Microsoft Teams phishing
Malware Activity
H score26
First: 21.08.2026 21:01
Last: 21.08.2026 21:01
Sources 1
About this happening:
The SynkLoader malware family is being pushed through Microsoft Teams phishing to steal credentials with a fake Windows lock screen, giving attackers remote access...
SynkLoader malware distribution via Microsoft Teams phishing
Malware ActivityAbout this happening: The SynkLoader malware family is being pushed through Microsoft Teams phishing to steal credentials with a fake Windows lock screen, giving attackers remote access...
Timeline
-
02.10.2026 20:33 2 articles · 2h ago
Antino Windows backdoor activity using Microsoft 365 dead drops
Initial DisclosureThe earliest observed stage used spear-phishing to deliver an HTA/WSF chain that ultimately loaded Antino on Windows systems. The first-stage design used downloader components and legitimate Microsoft binaries to prepare covert Outlook and OneDrive command handling.
Show sources
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign — thehackernews.com — 02.10.2026 20:33
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign — thehackernews.com — 02.10.2026 20:33