Government ministries, legislative bodies, and prominent policy organizations across Asia have become the primary targets of a sophisticated, targeted cyber espionage campaign orchestrated by a China-nexus threat actor. Cybersecurity researchers are tracking this emerging threat cluster under the internal identifier UAT-11587, noting that the campaign relies on a previously undocumented, highly versatile backdoor codenamed Antino. The intrusion set first surfaced in September 2025 during an initial wave of spear-phishing attacks directed squarely against Taiwan’s academic institutions, prominent think tanks, and civil society policy communities. Since those early detections, the scope of the campaign has expanded dramatically, affecting at least 16 distinct entities spread across eight different countries throughout Asia, while also occasionally branching out into other strategic geopolitical regions.

According to telemetry and threat intelligence gathered by Cisco Talos, the geographic spread of the targeted organizations underscores the geopolitical motivations driving the campaign. Alongside Taiwan, the threat actor has launched cyber attacks against government and policy infrastructure in India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. Furthermore, investigators uncovered evidence suggesting that UAT-11587 broadened its operational horizons further west, training its sights on organizations located in Syria around May 2026. This wide-ranging yet strategically focused target list highlights an intelligence-gathering operation explicitly aligned with the broader foreign policy and regional security interests traditionally associated with China-nexus advanced persistent threat groups.

While establishing definitive attribution in cyberspace remains a complex and often elusive challenge, Cisco Talos researchers have expressed high confidence in linking UAT-11587 to a China-nexus threat actor. This assessment is underpinned by multiple technical artifacts discovered during forensic analyses of the malicious infrastructure and lure documents. Investigators noted the recurring presence of Simplified Chinese language metadata, along with the "zh-CN" locale identifiers embedded within the documents used as operational lures. Additionally, analysis of email headers associated with the spear-phishing messages revealed activity timestamps falling strictly within the UTC+08:00 time zone, aligning with standard business hours in China. The thematic nature of the chosen lures—consistently focusing on Taiwanese political affairs, legislative matters, civil defense initiatives, regional government policies, maritime disputes, and diplomatic security—further reinforces this analytical conclusion.

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

The timing of the campaign has also displayed distinct operational shifts and intensive periods of activity. Attacks mounted by UAT-11587 exhibited a notable surge between March and early June 2026. During this broader window of heightened aggression, researchers identified a particularly intense, concentrated wave of cyber intrusions that took place on June 8 and 9, 2026. Over the course of these two days, the threat actor aggressively targeted dozens of separate systems and networks heavily associated with critical government information technology infrastructure. This concentrated push indicates that the operators were working to meet specific intelligence collection milestones or hastily harvesting data from compromised networks before defenders could detect and remediate the intrusions.

At the heart of this campaign’s technical infrastructure is the Antino backdoor, a sophisticated piece of malware compiled in the Rust programming language specifically to target the Windows operating system. Security researcher Ashley Shen detailed the capabilities of the implant, noting that Antino is engineered to support deep host reconnaissance, command execution via standard command-line interfaces and PowerShell, file transfers, and in-memory shellcode loading. Crucially, the backdoor maintains persistence on compromised hosts and bypasses traditional network defense mechanisms by eschewing conventional command-and-control servers. Instead of connecting to a dedicated external server that could be easily blocked by perimeter firewalls, Antino operates its native command-and-control channel exclusively through Microsoft 365, leveraging the Microsoft Graph API to interact directly with legitimate Outlook and OneDrive accounts as dead drops.

The initial access vector employed by UAT-11587 relies heavily on meticulously crafted spear-phishing emails. Rather than utilizing generic templates, the threat actor appears to conduct extensive reconnaissance on targeted organizations, researching key personnel, ongoing projects, and internal terminology to craft highly convincing communications. To maximize the likelihood that recipients will open the malicious messages and trust their origins, the actors frequently spoof sender identities trusted by the intended victims. By skillfully forging sender details, the emails are designed to bypass standard email authentication frameworks such as SPF and DMARC checks, ensuring that the communications successfully land inside the primary inboxes of high-value targets rather than being relegated to spam folders.

One particularly deceptive social engineering technique identified in this campaign involved the faithful visual reconstruction of Gmail’s native attachment preview widget directly within the HTML body of incoming emails. To achieve this, the threat actor replicated the exact visual styling of a legitimate Gmail attachment card by embedding four inline PNG images as Base64-encoded MIME parts. The entire simulated attachment card was then wrapped inside an invisible anchor tag pointing to an attacker-controlled URL hosted on Cloudflare Pages. When a targeted user opened the email inside a web browser, the email client’s renderer dutifully displayed the attacker-manipulated HTML, producing a convincing fake attachment preview that was practically indistinguishable from an authentic document attachment.

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Once a recipient interacts with the deceptive email and clicks the malicious link, the attack sets off a complex, multi-stage infection chain. The Cloudflare-hosted URL initiates the download of an HTML Application or a Windows Script File. Upon execution, this initial stager retrieves a secondary JavaScript downloader and decryptor. This component subsequently triggers a .NET deserialization chain designed to load a custom .NET downloader and launcher known as "TestAssembly.dll." This launcher is tasked with retrieving and staging the final operational payload on the compromised machine.

The ultimate implant, designated as "slc.dll," is introduced into the operating system through a technique known as DLL sideloading, utilizing a legitimate, Microsoft-signed binary named "GatherOsState.exe" to execute the malicious code quietly under the radar of security software. Once successfully launched, the Rust-compiled Antino backdoor establishes its covert communication channel with Microsoft 365. Rather than querying a malicious IP address, the malware utilizes Outlook for fetching commands and OneDrive for executing heartbeats and facilitating file transfers. Specifically, the backdoor checks the threat actor’s Outlook mailbox folder every ten seconds, scanning specifically for incoming messages carrying the unique subject prefix "commandreq[session_id]."

Once operational, Antino equips its handlers with a comprehensive suite of remote access capabilities. The backdoor can seamlessly enumerate running processes, inspect directory structures, execute arbitrary PowerShell scripts, run shellcode, launch operator-supplied programs, and issue commands directly through the Windows command interpreter. Furthermore, researchers noted that the backdoor frequently leverages the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell commands through trusted operating system components. While this living-off-the-land tactic can complicate immediate behavioral attribution back to the original implant, security analysts emphasize that it does not entirely erase the observable telemetry left behind in PowerShell logs, file-creation records, and Windows Registry modifications.

In the broader threat intelligence landscape, analysts have previously attempted to connect intrusion sets exhibiting similar technical traits. Prior reports from security firms like Symantec and Carbon Black characterized a China-aligned hackers-for-hire group known as Jewelbug as engaging in both targeted espionage operations and financially motivated cryptocurrency fraud. Because of certain operational overlaps, investigators evaluated whether UAT-11587 shared direct ties with Jewelbug or related clusters like CL-STA-0049, Earth Alux, Ink Dragon, and REF7707. However, subsequent deep-dive investigations conducted by Cisco Talos found no definitive evidentiary connection linking the espionage-focused Antino campaign to Jewelbug’s financially driven activities. Consequently, Talos designated UAT-11587 as a distinct, independent activity set, highlighting the complex, fluid, and often overlapping nature of threat actor groups operating out of the region.

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

As government agencies, diplomatic missions, and policy research institutions across Asia continue to navigate an increasingly hostile cyber threat landscape, the discovery of the Antino backdoor and the UAT-11587 intrusion set serves as a stark reminder of the evolving sophistication behind regional espionage campaigns. By combining advanced evasion techniques, abuse of trusted cloud services like Microsoft 365, and highly targeted social engineering ploys, modern threat actors continue to refine their methods for long-term, undetected persistence inside critical institutional networks. Cybersecurity defenders advise organizations within the region to maintain heightened vigilance, monitor unusual email rendering patterns, and scrutinize anomalous API interactions involving cloud productivity suites to mitigate the risks posed by these stealthy intrusion campaigns.

Leave a Reply

Your email address will not be published. Required fields are marked *