ThreatPaper
State-SponsoredMalwareHigh

UAT-11587 deploys Antino backdoor using Microsoft 365 as dead-drop C2 against Asian governments

By Sethu Satheesh · 6 Oct 2026 · 14 min read

Threat Actor: UAT-11587 (China-nexus, per Cisco Talos) · Target: Government, defense, diplomatic and policy organizations across Asia and the Middle East

Source: blog.talosintelligence.com


Executive Summary

On September 30, 2026, Cisco Talos published research on a cluster of cyber-espionage activity it tracks as UAT-11587, targeting government and policy organizations across Asia with a previously undocumented Rust-compiled Windows backdoor named Antino.1 Talos first observed the activity in September 2025 and traced it through July 2026, during which it identified at least 16 affected or targeted institutional environments across eight countries and approximately 350 compromised endpoints.1 Talos assesses with high confidence that UAT-11587 is China-nexus, "based on the totality of corroborating technical and operational evidence, rather than any single indicator," and with moderate confidence that it is conducting an intelligence-gathering operation.1

The campaign's defining feature is its command-and-control design. Antino communicates exclusively through Microsoft 365, using the Microsoft Graph API to interact with Outlook and OneDrive objects as dead drops rather than relying on a conspicuous dedicated command server.1 The implant authenticates to Graph through an OAuth 2.0 client-credentials flow tied to a registered Entra ID application, polls an Outlook mailbox for tasking every 10 seconds, and uses OneDrive folders for registration, heartbeats, and file transfer.1 Delivery leaned heavily on legitimate cloud infrastructure — Cloudflare Pages and Cloudflare R2 for staging, with Amazon CloudFront as an alternate — so that most of the infection chain rode inside widely trusted HTTPS traffic.1

Talos assesses with moderate-to-high confidence that the campaign targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria, spanning defense and national security, foreign affairs, law enforcement and border security, legislatures, government IT, think tanks and universities, and civil-society and human-rights bodies.1 The intrusion typically began with spear-phishing that impersonated a trusted organization and recreated Gmail's attachment interface, followed by a five-stage infection chain culminating in DLL side-loading of Antino through a Microsoft-signed binary.1

The incident matters for two reasons beyond the victim list. First, the dead-drop-over-Microsoft-365 design collapses the distinction between malicious C2 and ordinary enterprise cloud traffic, defeating controls that key on unfamiliar destinations. Second, attribution is genuinely contested at the group level: Symantec, in research published August 13, 2026, attributes the Antino-related espionage to a named China-based APT it calls Jewelbug (aka Earth Alux, REF7707, CL-STA-0049) and ties it to a parallel cryptocurrency-fraud business, whereas Talos found overlaps but "could not independently verify a connection" and tracks UAT-11587 as a separate activity set.23

Verification of Claims

  1. Claim: Antino uses Microsoft 365 (Outlook and OneDrive) via Graph as its C2. → Verified → Talos documents that Antino "communicates exclusively through Microsoft 365, using the Microsoft Graph API to interact with Outlook and OneDrive," authenticating via an OAuth 2.0 client-credentials flow, polling Outlook for commands every 10 seconds, and using OneDrive paths such as /antino/heartbeats/{id}.json for beaconing.1

  2. Claim: The campaign compromised approximately 350 endpoints across eight countries. → Verified → Talos states: "Our investigation reveals approximately 350 compromised endpoints across eight countries," with the largest concentrated wave on June 8–9, 2026, when "around 57 newly observed endpoints associated with India" appeared. This endpoint count is a different denominator from the institution count.1

  3. Claim: At least 16 institutional environments were affected or targeted. → Partially verified → Talos reports "at least 10 confirmed and five probable affected institutional environments, plus one additional intended target" — 16 in total, but only 10 are confirmed compromises. Characterizing all 16 as penetrated, as some coverage does, overstates the confirmed record.14

  4. Claim: UAT-11587 is China-nexus. → Partially verified → Talos assesses this "with high confidence," expressly as a nexus judgment on "the totality of corroborating technical and operational evidence," not a claim of direct state tasking. Talos does not use the phrase "state-sponsored"; downstream coverage that does is inflating the stated confidence.15

  5. Claim: UAT-11587 is the APT "Jewelbug." → Unverified → Symantec attributes the Antino-related espionage to a group it names Jewelbug; Talos "identified overlaps" but "could not independently verify a connection between the espionage campaign and Jewelbug's financially motivated activity" and tracks UAT-11587 separately.23

Timeline

Date Actor Event Source
September–November 2025 UAT-11587 Earliest reviewed activity; Philippines-themed lures delivered via direct email attachment 1
October 2025 UAT-11587 Antino Gen1 builds observed 1
December 2025–January 2026 UAT-11587 Antino Gen2 build period (AntinoApp manifest, revised session-ID and heartbeat behavior) 1
January 2026 UAT-11587 Two further Philippines-focused HTA campaigns; standalone fake-installer delivery branch begins 1
March 2026 UAT-11587 Talos identifies the campaign while investigating spear-phishing against Taiwan's academic, think-tank and civil-society community; message recreated Gmail's attachment interface 1
March–early June 2026 UAT-11587 Activity accelerates across the Philippines and Taiwan, then Cambodia, Myanmar, Syria, Pakistan and Thailand 1
June 8–9, 2026 UAT-11587 Largest concentrated wave; ~57 newly observed endpoints associated with India 1
July 2026 UAT-11587 By this point ≥16 institutional environments across eight countries, ~350 endpoints 1
August 13, 2026 Symantec Publishes Jewelbug research attributing Antino espionage and parallel crypto fraud to one China-based group 3
September 30, 2026 Cisco Talos Publishes UAT-11587 / Antino report 1
October 2, 2026 The Hacker News Reports the campaign, keeping endpoint and institution counts distinct 2

Attack Anatomy

Initial access and sender spoofing

Delivery began with spear-phishing. In the Taiwan operation, the message "recreated Gmail's attachment interface" using inline Base64-encoded PNG images, with the fake attachment card wrapped in an anchor pointing to an attacker-controlled Cloudflare Pages URL carrying an ?m= recipient identifier for per-target logging (T1566.002, T1204.001).1 Messages were sent through Migadu with the attacker-controlled osc-cdn[.]com domain as the RFC5321 envelope sender, while the RFC5322 From header displayed the impersonated organization's identity (T1684.001).1 SPF passed for the envelope domain; DMARC detected the misalignment and failed, but the displayed domain used a non-enforcing p=none policy, so the receiving provider still delivered the message.1 Earlier (September–November 2025) campaigns used direct email attachments instead (T1566.001).1

Stage 1 — HTA/WSF stager

The Cloudflare Pages link delivered an HTA file executed by mshta.exe (T1218.005). It "hides and resizes its window, emits a tracking request to an invariant Cloudflare Pages beacon, and imports the next JavaScript stage."1 A hidden image causes mshta.exe to request the fixed host oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev with the lure title in the path and ?track in the query, letting the operator correlate execution to a specific lure.1 Paired WSF variants achieve the same via Windows Script Host, sending an HTTP HEAD to the tracking host before loading the next stage.1

Stage 2 — JScript downloader and decryptor

HTA-hosted Microsoft JScript (T1059.007), delivered from Cloudflare R2 (pub-<32-hex>[.]r2[.]dev) or Amazon CloudFront (d2nq35tel3ucuo[.]cloudfront[.]net), retrieves three encrypted resources — an encrypted JScript orchestrator and two serialized .NET gadget resources — then decrypts and executes the orchestrator in memory to initiate a .NET 4.x deserialization chain (T1140).1

Stage 3 — .NET BinaryFormatter deserialization

The JScript instantiates COM-visible .NET classes and passes attacker-controlled serialized data into BinaryFormatter. The embedded gadget chain drives execution, loading and running an embedded .NET assembly, TestAssembly.dll, inside the script host process mshta.exe (T1620).1

Stage 4 — TestAssembly.dll downloader/launcher

TestAssembly.dll downloads a lure-specific decoy document and a three-file DLL-side-loading bundle from cloud infrastructure (T1105), opens the decoy for the victim (T1204.002), writes the bundle to a writable staging directory, and launches the Microsoft-signed GatherOsState.exe.1

Stage 5 — DLL side-loading of Antino

GatherOsState.exe, a legitimate Microsoft-signed Windows ADK binary, is abused to side-load slc.dll — the Antino backdoor (T1574.001).1 The staging directory observed was %LOCALAPPDATA%\Windows GatherOSStateKit\, and files were retrieved with randomized nonstandard extensions (e.g. .luy, .pzs, .syk).1

Command and control, discovery and exfiltration

Antino authenticates to Microsoft Graph via the OAuth 2.0 client-credentials flow of a registered Entra ID application (T1550.001), reaching only graph.microsoft.com and login.microsoftonline.com (T1071.001).1 It pulls tasking from an Outlook mailbox every 10 seconds using subjects command_req_[session_id] / command_res_[session_id], and uses OneDrive as a dead drop — /antino/heartbeats/{id}.json for check-ins, /antino_downloads/ for exfiltrated data, /antino_uploads/ for operator toolkit delivery (T1102.002, T1567.002).1 Backdoor commands cover reconnaissance (system_info, T1082; ps, T1057; list_files, T1083), execution (cmd via cmd.exe /C, T1059.003; powershell, T1059.001; execute_program; load_shellcode in memory, T1620), file transfer (upload_file, download_file), and persistence (add_to_run, a HKCU Run value, T1547.001).1 Configuration is stored in a custom .cfg PE section, XORed with the alternating key 0xAB 0xCD; an optional use_sleep_mask routine hooks Sleep and VirtualAlloc and uses a vectored exception handler to encrypt the payload region in memory between sleeps (T1027).1

Loading diagram...

Threat Actor Profile

Name: UAT-11587 (Cisco Talos intel-tracked cluster) Aliases: Overlaps with Symantec's Jewelbug (reported aliases Earth Alux, REF7707, CL-STA-0049); Talos tracks UAT-11587 as a separate activity set23 Attribution confidence: China-nexus, high confidence, per Cisco Talos, on "the totality of corroborating technical and operational evidence, rather than any single indicator"; intelligence-gathering purpose assessed at moderate confidence1 Motivation: Espionage / intelligence collection against government, defense, diplomatic and policy targets1

Talos named the malware after finding AntinoApp in its Windows application manifest and repeated antino directory names in PDB and Rust source paths (D:\a\antino\antino\...) across variants.1 Two generations were observed: Gen1 (October 2025) and Gen2 (December 2025–January 2026), differing in session-ID generation and heartbeat behavior, with Gen2 adding the AntinoApp manifest.1 The actor also distributed standalone Antino builds through fake installers at microsoft-flash[.]com and wps-cn[.]com (flashcenter_pp_ax_install_en.exe); the choice of wps-cn[.]com may indicate targeting of Chinese-speaking users.1 Symantec separately reports its Jewelbug cluster used additional implants (a Linux backdoor "ClientKing," a "PDF Viewer" browser extension) and held a victim database of more than one million implant check-in rows, 580,000+ browser cookies and 2,300+ exfiltrated email bodies across 15+ government webmail tenants — figures tied to Symantec's cluster, not independently confirmed by Talos for UAT-11587.3

MITRE ATT&CK techniques (IDs verified live on attack.mitre.org):

ID Technique
T1566.001 Phishing: Spearphishing Attachment
T1566.002 Phishing: Spearphishing Link
T1684.001 Social Engineering: Impersonation
T1204.001 User Execution: Malicious Link
T1204.002 User Execution: Malicious File
T1218.005 System Binary Proxy Execution: Mshta
T1059.007 Command and Scripting Interpreter: JavaScript
T1059.001 Command and Scripting Interpreter: PowerShell
T1059.003 Command and Scripting Interpreter: Windows Command Shell
T1140 Deobfuscate/Decode Files or Information
T1620 Reflective Code Loading
T1574.001 Hijack Execution Flow: DLL
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
T1550.001 Use Alternate Authentication Material: Application Access Token
T1071.001 Application Layer Protocol: Web Protocols
T1102.002 Web Service: Bidirectional Communication
T1105 Ingress Tool Transfer
T1082 System Information Discovery
T1057 Process Discovery
T1083 File and Directory Discovery
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
T1027 Obfuscated Files or Information

OPSEC: C2 confined to trusted Microsoft domains; staging inside Cloudflare Pages/R2 and CloudFront; per-recipient and per-lure execution tracking; randomized file extensions; in-memory assembly loading and optional sleep-mask memory encryption to evade scanners.1

Technical Indicators

actor_domains:
  - osc-cdn[.]com           # spear-phishing RFC5321 envelope-sender domain
  - microsoft-flash[.]com   # standalone fake-installer Antino delivery
  - wps-cn[.]com            # standalone fake-installer Antino delivery
execution_tracking:
  - oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev   # invariant Cloudflare Pages beacon (?track)
cloudflare_pages_delivery:
  - my-3lyt6wcp[.]pages[.]dev
  - my-qc39r814[.]pages[.]dev
  - my-662ylt3w[.]pages[.]dev
  - my-6g16qsfe[.]pages[.]dev
  - my-goq6xmbm[.]pages[.]dev
  - my-h3qli6kq[.]pages[.]dev
  - my-sv7c1fzs[.]pages[.]dev
  - my-u0up9qri[.]pages[.]dev
  - my-vtsdod2n[.]pages[.]dev
  - my-wgoxp32b[.]pages[.]dev
cloudflare_r2_staging:
  - pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev
  - pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev
cloudfront_staging:
  - d2nq35tel3ucuo[.]cloudfront[.]net
ip_addresses:
  - 103.27.110[.]220   # historical serving IP for wps-cn[.]com
standalone_delivery_urls:
  - hxxps://microsoft-flash[.]com/download/flashcenter_pp_ax_install_en.exe
  - hxxps://www[.]wps-cn[.]com/downloads/flashcenter_pp_ax_install_en.exe
antino_c2:
  graph_endpoints:
    - graph.microsoft[.]com
    - login.microsoftonline[.]com
  onedrive_paths:
    - '/antino/heartbeats/{id}.json'   # check-in
    - '/antino_downloads/{file}'        # exfiltration
    - '/antino_uploads/{file}'          # operator toolkit delivery
  outlook_subjects:
    - 'command_req_[session_id]'
    - 'command_res_[session_id]'
  poll_interval: every 10 seconds
host_artifacts:
  staging_dir: '%LOCALAPPDATA%\Windows GatherOSStateKit\'
  sideload_binary: 'GatherOsState.exe (Microsoft-signed Windows ADK, abused)'
  sideloaded_dll: 'slc.dll (Antino)'
  persistence: 'HKCU Run value (add_to_run command)'
  config: 'custom .cfg PE section, XOR key 0xAB 0xCD'
  assembly_guid: 'b2b3adb0-1669-4b94-86cb-6dd682ddbea3 (TestAssembly.dll)'
pdb_paths:
  - 'D:\a\antino\antino\target\x86_64-pc-windows-msvc\release\deps\slc_template.pdb'
  - 'D:\a\antino\antino\target\x86_64-pc-windows-msvc\release\deps\antino_client_template.pdb'
  - 'D:\a\antino\antino\target\i686-pc-windows-msvc\release\deps\antino_client_template.pdb'
sha256_antino_samples:
  - 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff  # Gen2 slc.dll
  - e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530  # Gen2 slc.dll
  - e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb  # Gen2 slc.dll
  - fdbd047031c13a17c9f491c9355f44d587584ebe2b8927be8482e6c236c8e1c1  # Gen2 slc.dll
  - 1fadc90b61ce536abda78eb387a7f3d745f00c16775d3f762845ccc0fde567da  # Gen1 slc.dll
  - 40e7e77aff603f4c2ef17b3bc8ea836e714d0734a1e5b946e52f95536ec5c91d  # Gen1 standalone
  - 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd  # Gen2 standalone
  - 971cb2448b5d67dcc1f5eaa10d12e77f213035ad31230dc2ac7a510610a2059d  # Gen2 standalone
  - 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3  # Gen2 standalone
  - b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e  # Gen2 standalone
  - 5c5c060b272cd4a5c3767edc0e9478bd35b7e1756e183d0446a5491bd65519cb  # standalone
  - ca14ad0344dc7216f6da29a5cbe4237d886cc5257e8c3a48fb4885a311c9b800  # memory image
sha256_testassembly_downloaders:
  - d753a615aedf8e58ffc75b2b7ebd320c0cbe6bcb5cbb885db749a2a85c55d3bf
  - 133a46ba41136ca21c93fb08c28446826d8c0d9b7923a16f2d152d595a710098
  - 9fc50cf28f86201fda8306926817b1ede41fdd993202515905dd072f6803542f
  - d4cb2f5df16ec9b9c5b796ae55848534e15d4f8b8806f0431108fc7a99a2548a
  - 131ac3e0df777910e0a32e43d5744bccb0490750d4c2adc359da41d76d383c46
note: >
  Representative subset. Talos published fuller lists of HTA/WSF stagers, JScript
  downloaders, encrypted orchestrators and BinaryFormatter gadget resources; see the
  primary report for the complete IOC set. Network indicators are defanged.

As of October 6, 2026, no law enforcement action, indictment, sanction, or government advisory tied specifically to UAT-11587 or the Antino backdoor had been published. The activity is documented in private-sector vendor research: Cisco Talos's report of September 30, 2026, and Symantec's Jewelbug research of August 13, 2026.13 No national CERT or agency advisory naming UAT-11587 or Antino was located as of that date.

Impact Assessment

  • Confirmed: At least 10 confirmed affected institutional environments, with approximately 350 compromised endpoints across eight countries between September 2025 and July 2026, per Cisco Talos.1
  • Confirmed: Antino's exclusive use of Microsoft 365 (Graph/Outlook/OneDrive) for C2, documented by Talos from recovered samples and developer artifacts.1
  • Reported, not independently confirmed: Five probable affected environments and one additional intended target, raising the institution total to at least 16; targeting of organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria is assessed at moderate-to-high confidence.1
  • Reported, not independently confirmed (separate cluster): Symantec's Jewelbug figures — 1M+ implant check-ins, 580,000+ cookies, 2,300+ exfiltrated emails across 15+ government webmail tenants — which Talos did not confirm for UAT-11587.3
  • Unknown: The specific data exfiltrated from each victim, and whether UAT-11587 and Jewelbug are operated by the same entity.12

Lessons and Defensive Recommendations

For SOC/defenders:

  • Treat Microsoft Graph traffic as a potential C2 channel: baseline and alert on OAuth client-credentials token grants to newly registered Entra ID apps, and on OneDrive/Outlook automation that does not map to an interactive user session.1
  • Hunt for the dead-drop pattern — Outlook items with command_req_/command_res_ subjects and OneDrive paths under /antino/heartbeats/, /antino_downloads/, /antino_uploads/.1
  • Alert on mshta.exe spawning script hosts and making outbound requests to *.pages.dev, *.r2.dev or cloudfront.net, and on GatherOsState.exe executing from %LOCALAPPDATA%\Windows GatherOSStateKit\.1

For developers / platform teams:

  • Audit signed binaries that load external libraries and restrict their DLL search paths; GatherOsState.exe side-loading slc.dll is the control that failed here.1
  • Constrain or disable legacy BinaryFormatter deserialization in .NET surfaces reachable from script hosts.1

For cloud / email administrators:

  • Move DMARC from p=none to enforcing (quarantine/reject); the spoof succeeded because the impersonated domain's policy only monitored.1
  • Scope Entra ID application permissions tightly and review consent grants for Mail and Files access.1

For leadership:

  • Assume adversaries will route C2 through the same SaaS platforms the organization trusts; detection investment should shift from blocking unfamiliar destinations to behavioral analytics on sanctioned cloud services.1

Sources

Footnotes

  1. Cisco Talos — China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor — September 30, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34 ↩35 ↩36 ↩37 ↩38 ↩39 ↩40 ↩41 ↩42 ↩43 ↩44 ↩45 ↩46 ↩47 ↩48 ↩49 ↩50 ↩51 ↩52 ↩53 ↩54 ↩55 ↩56

  2. The Hacker News — Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign — October 2, 2026 ↩ ↩2 ↩3 ↩4 ↩5

  3. Symantec (Broadcom) — Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side — August 13, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7

  4. CybernewsAI — China's UAT-11587 Targets Asian Governments via Antino Backdoor — September 30, 2026 ↩

  5. Security Online — UAT-11587 Targets Asian Governments With Antino Backdoor — October 2, 2026 ↩

Topics: #uat-11587#antino#china-nexus#cisco-talos#microsoft-graph#onedrive-c2#dll-sideloading#cyber-espionage#jewelbug#cloudflare#rust-malware
Original Incident Report →

Related Research

ESET Research documents SparroWocky, a new C++ backdoor from the China-aligned FamousSparrow APT that has almost exclusively targeted Latin American government organizations since mid-2025 — including an entity directly involved in Panama's contested port concession dispute.

State-SponsoredMalware

Russia's FSB-linked Star Blizzard used a new delivery technique, RedFlick, in 13 phishing campaigns affecting 100+ US and UK organizations to deploy its CosmicPulse backdoor in 2026.

State-SponsoredSocial EngineeringMalware

Rapid7's October 2, 2026 report details AVERAT and new BPFDoor/Rekoobe Linux implants that hide C2 in SMTP port 25 to mimic South Korean (SpamSniper) and Taiwanese (ShareTech) mail-security appliances and relay through compromised NAS, DVR and SMB devices against telecom targets.

Malware