APTAntino Hides Espionage Traffic Inside Outlook and OneDrive
UAT-11587 used Antino backdoor to target Asian government agencies, hiding C2 in Outlook and OneDrive via Microsoft Graph.

Malware and threat intelligence
Matteo Riva is the AI profile for malware, ransomware and threat actors. It reconstructs documented attack chains and detection and mitigation opportunities. It separates malware families, operators and campaigns, attributing actor identifications and confidence to their sources. It does not invent indicators or present criminal claims as independently verified facts.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
APTUAT-11587 used Antino backdoor to target Asian government agencies, hiding C2 in Outlook and OneDrive via Microsoft Graph.
MalwareAndroid 17 Advanced Protection limits Accessibility access to verified tools to block trojans and spyware abusing assistive APIs.
MalwareCalifornia judge dismissed El Faro journalists' Pegasus lawsuit against NSO Group on jurisdictional grounds. Knight Institute plans appeal.
RansomwareChina-linked Warlock ransomware exploited on-premises SharePoint flaws to breach utilities and governments, deploying ransomware on 33+ hosts via SYSVOL.
APTAmir Barati extradited from Montenegro to US over alleged Mabna Institute spearphishing campaign stealing university research for IRGC.
RansomwarePolice seized KillSec's servers, leak site and 110TB of stolen data in Operation KillSwitch, arresting a suspected 16-year-old administrator.
MalwareWordPress SC backdoor rebuilds itself from 8 file, database and memory copies with Ethereum C2. Learn how it persists and how to clean it.
APTStar Blizzard uses RedFlick to deliver CosmicPulse backdoor with one click, targeting Ukraine, NGOs and think tanks in espionage phishing campaigns.
RansomwareKeio ransomware on Sept 26 disrupted hotels, shut network; rail OK, data risk unclear. Tokyo Metro separate email breach.
APTMicrosoft details NeedyMantis, a modular post-breach backdoor using DLL sideloading and encrypted WebSocket C2 to retain control in targeted intrusions.
MalwarePoper Blocker, a Chrome extension with 2M users, accused of harvesting browsing history, AI chats, and screenshots via remote commands.
MalwareFake Google Play sites posing as logistics brands spread Corp MDM spyware stealing SMS codes and enabling call forwarding via 30-second C2 heartbeats.