A China-nexus campaign attributed to UAT-11587 reportedly targeted Asian government and policy organizations with the Rust-based Antino backdoor, using Microsoft 365 services for command-and-control. Security teams should investigate anomalous Outlook and OneDrive behavior, correlate it with endpoint activity, and apply the source vendor’s detection guidance.

Source: The Hacker News

This report is based on the cited source. Organizations should consult vendor guidance and their own telemetry before acting.

By Allan