Trusted Microsoft 365 traffic hides a Windows espionage backdoor

Update 07 — English headline pending. Government, defense, diplomatic, academic and policy organizations were compromised by a Windows backdoor that placed its native command channel inside Microsoft 365.

Daily Cyber News: Update 07 — English headline pending

Government, defense, diplomatic, academic and policy organizations were compromised by a Windows backdoor that placed its native command channel inside Microsoft 365. By July 2026, the campaign had reached approximately 350 endpoints across eight countries. Investigators identified 10 confirmed and five probable affected institutional environments and linked the activity to China with high confidence.

Key context: Tailored phishing emails and fake software installers delivered the malware.

Additional detail: That use of common cloud services can make malicious traffic blend with legitimate business activity.

For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

Topics: cybersecurity news, cybersecurity, cyber risk, phishing, malware, microsoft 365, windows.

Trusted Microsoft 365 traffic hides a Windows espionage backdoor
Broadcast by