Antino backdoor abuses Outlook and OneDrive for C2 in China-nexus espionage across Asia
Cisco Talos says China-nexus actor UAT-11587 used a new Rust backdoor, Antino, that hides its command traffic in Outlook and OneDrive to spy on government and policy bodies in eight Asian countries.
At a glance
- Cisco Talos tracks the actor as UAT-11587 and assesses with high confidence that it is China-nexus
- Talos counted 16 affected or targeted environments in eight Asian countries and roughly 350 compromised endpoints between September 2025 and July 2026
- Antino is a Rust backdoor that uses Microsoft Graph, Outlook messages and OneDrive files as dead drops instead of a dedicated C2 server
- Talos published ClamAV signatures, Snort rules and more than 100 IOCs on GitHub
A China-nexus threat actor has spent about eleven months spying on government and policy organizations across Asia with a previously undocumented backdoor that hides its command-and-control traffic inside Microsoft 365, Cisco Talos said in research published on September 30. Talos tracks the cluster as UAT-11587 and the Rust-based backdoor as Antino. According to the researchers, the malware uses Outlook mailboxes and OneDrive storage as dead drops, which lets its traffic blend in with ordinary corporate cloud activity.
What happened
Talos said it first observed UAT-11587 activity in September 2025. Talos said it uncovered the campaign while investigating spear-phishing aimed at Taiwan's academic, think tank and civil society policy community in March 2026, although the earliest activity it found used Philippines-themed lures. By July 2026, Talos had identified 16 affected or targeted institutional environments — 10 confirmed, five probable and one intended target — with roughly 350 compromised endpoints across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. The Hacker News reported that attacks spiked between March and June 2026, and Talos said a wave on June 8–9 added about 57 new endpoints in India.
Targets included defense and military bodies, foreign affairs, justice and legislative institutions, government IT services, think tanks, universities and civil society groups, according to Talos. Recovered decoys included a Taiwan information warfare workshop document, a reproduction of a Taiwan Ministry of Finance ruling and details of a CSIS Indo-Pacific forecast event, Talos said.
Technical details
Talos described a five-stage infection chain. Spear-phishing emails with spoofed senders, sometimes showing a fake Gmail attachment preview built from Base64-encoded images, lead to an HTA or WSF stager hosted on Cloudflare Pages. A JScript downloader then pulls encrypted components from Cloudflare R2 or Amazon CloudFront, a .NET deserialization step loads TestAssembly.dll, and finally the Microsoft-signed GatherOsState.exe sideloads the Antino payload as slc.dll.
Antino authenticates to an Entra ID application through Microsoft Graph, Talos said. It polls Outlook every 10 seconds for messages whose subject starts with command_req_, and writes heartbeats and transferred files to OneDrive folders such as /antino/heartbeats/. Its features include host reconnaissance, cmd and PowerShell execution, file upload and download, in-memory shellcode loading and Registry Run key persistence, along with a sleep-mask technique to hide shellcode in memory.
Talos based its attribution on Simplified Chinese metadata and UTC+8 timestamps in decoy documents, build paths that point to the mainland China Rust mirror rsproxy.cn, and CloudFront infrastructure shared with China-nexus activity tracked as UNC6384. The researchers also noted overlaps with Symantec's separate reporting on Antino, which Symantec linked to a group it calls Jewelbug. Talos said it tracks UAT-11587 separately because it could not independently verify Jewelbug's connection to cryptocurrency fraud activity.
Who is affected
According to the report, the main targets are government ministries, legislatures, defense bodies and policy researchers in South and Southeast Asia and Taiwan. Any organization that relies on Microsoft 365 could be exposed to similar techniques, because the C2 traffic goes to legitimate Microsoft endpoints.
What to do
Talos released 20 ClamAV signatures, Snort rules 1:66880 to 1:66882, and more than 100 indicators in its GitHub IOC repository. Defenders should review Entra ID application registrations and unusual client-credential Graph activity, monitor mshta.exe launching remote HTA files, flag GatherOsState.exe running outside normal deployment paths, and treat links to Cloudflare Pages or R2 in unsolicited policy-themed emails with caution.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



