Trusted Microsoft 365 traffic hides a Windows espionage backdoor
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, October 2nd, 2026.
Government, defense, diplomatic, academic and policy organizations were compromised by a Windows backdoor that placed its native command channel inside Microsoft 365. By July 2026, the campaign had reached approximately 350 endpoints across eight countries. Investigators identified 10 confirmed and five probable affected institutional environments and linked the activity to China with high confidence.
Tailored phishing emails and fake software installers delivered the malware. Once installed, Outlook carried commands and responses, while OneDrive handled stolen files, incoming tools and status updates. The newer generation also used stored application credentials, allowing it to authenticate without an interactive user login.
That use of common cloud services can make malicious traffic blend with legitimate business activity. Leaders should require behavioral monitoring for cloud services even when the domains and applications are trusted. Defenders should review unusual Microsoft Graph activity, application credentials, mailbox polling and OneDrive transfers alongside endpoint evidence. Audit Microsoft 365 application access and investigate unusual Graph, Outlook and OneDrive behavior. The larger lesson is that trusted platforms can become covert infrastructure when identity and application behavior aren’t closely monitored.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.