<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Microsoft 365 (Outlook, OneDrive) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/microsoft-365-outlook-onedrive/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 10:18:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/microsoft-365-outlook-onedrive/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>China-nexus UAT-11587 Targets Asian Government Entities with Antino Backdoor</title><link>https://feed.craftedsignal.io/briefs/2026-09-china-uat11587/</link><pubDate>Wed, 30 Sep 2026 10:18:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-china-uat11587/</guid><description>China-nexus threat actor UAT-11587 is conducting long-term cyber espionage across Asia using the custom Rust-based Antino backdoor and Microsoft 365 services for command-and-control.</description><content:encoded><![CDATA[<p>Since September 2025, the China-nexus threat actor UAT-11587 has engaged in sustained espionage targeting government, defense, and policy research organizations across Asia, including Taiwan, India, the Philippines, and Cambodia. The campaign is characterized by high-effort spear-phishing lures and a multi-stage infection chain that culminates in the deployment of &quot;Antino,&quot; a custom, Rust-compiled Windows backdoor. Antino is notable for its use of legitimate Microsoft 365 services, specifically Outlook and OneDrive, as an obfuscated command-and-control (C2) channel, effectively bypassing traditional network-perimeter-based detection by masquerading as standard cloud traffic. With over 350 compromised endpoints identified across eight countries, the actor demonstrates significant operational capacity for long-term intelligence gathering, leveraging Cloudflare infrastructure for payload staging and execution tracking.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial Access: The actor sends spear-phishing emails containing tailored decoy documents or links to cloud-hosted malicious content.</li>
<li>Execution: The target is lured into executing a malicious downloader or HTA file, often hosted on Cloudflare infrastructure, which initiates the infection sequence.</li>
<li>Staging: The initial downloader fetches secondary-stage payloads from cloud-hosted staging environments.</li>
<li>Payload Delivery: The custom Antino backdoor is dropped and executed on the victim host.</li>
<li>Persistence: Antino establishes persistence mechanisms on the Windows endpoint to maintain access across reboots.</li>
<li>Reconnaissance: The malware performs host reconnaissance, collecting system information and user data.</li>
<li>C2 Communication: Antino communicates with Microsoft 365 (Outlook/OneDrive) to receive instructions and exfiltrate collected intelligence.</li>
<li>Exfiltration: Data is uploaded to the actor-controlled OneDrive storage or sent via Outlook, completing the espionage cycle.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The campaign has resulted in the compromise of approximately 350 endpoints across national security, diplomatic, legislative, and civil society sectors. Successful attacks allow the adversary to conduct deep reconnaissance, maintain persistent access, and exfiltrate sensitive policy and diplomatic intelligence. Given the focus on high-value public-sector targets, the breach of these systems represents a significant threat to regional stability and national security for the affected nations.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Monitor network traffic for unusual usage of Microsoft Graph APIs or excessive interaction with Microsoft 365 endpoints (Outlook/OneDrive) originating from servers or workstations that do not typically perform high volumes of office automation.</li>
<li>Implement strict controls on the execution of HTA files (HTML Applications) and block macros in untrusted documents via Group Policy.</li>
<li>Deploy EDR rules to monitor for Rust-compiled binaries executing from temporary directories or atypical user paths.</li>
<li>Block connections to the identified CloudFront infrastructure domain <code>d32tpl7xt7175h.cloudfront.net</code> if detected in proxy or DNS logs.</li>
<li>Conduct a hunt for the existence of unknown or unsigned Rust-compiled executables residing in common persistence locations like the Windows Startup folder or Run registry keys.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>espionage</category><category>windows</category><category>cloud-native-c2</category><category>rust</category><category>spear-phishing</category></item></channel></rss>