UAT-11587 deploys Antino backdoor using Microsoft 365 as dead-drop C2 against Asian governments
By Sethu Satheesh · 6 Oct 2026 · 14 min read
Threat Actor: UAT-11587 (China-nexus, per Cisco Talos) · Target: Government, defense, diplomatic and policy organizations across Asia and the Middle East
Source: blog.talosintelligence.com
Executive Summary
On September 30, 2026, Cisco Talos published research on a cluster of cyber-espionage activity it tracks as UAT-11587, targeting government and policy organizations across Asia with a previously undocumented Rust-compiled Windows backdoor named Antino.1 Talos first observed the activity in September 2025 and traced it through July 2026, during which it identified at least 16 affected or targeted institutional environments across eight countries and approximately 350 compromised endpoints.1 Talos assesses with high confidence that UAT-11587 is China-nexus, "based on the totality of corroborating technical and operational evidence, rather than any single indicator," and with moderate confidence that it is conducting an intelligence-gathering operation.1
The campaign's defining feature is its command-and-control design. Antino communicates exclusively through Microsoft 365, using the Microsoft Graph API to interact with Outlook and OneDrive objects as dead drops rather than relying on a conspicuous dedicated command server.1 The implant authenticates to Graph through an OAuth 2.0 client-credentials flow tied to a registered Entra ID application, polls an Outlook mailbox for tasking every 10 seconds, and uses OneDrive folders for registration, heartbeats, and file transfer.1 Delivery leaned heavily on legitimate cloud infrastructure — Cloudflare Pages and Cloudflare R2 for staging, with Amazon CloudFront as an alternate — so that most of the infection chain rode inside widely trusted HTTPS traffic.1
Talos assesses with moderate-to-high confidence that the campaign targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria, spanning defense and national security, foreign affairs, law enforcement and border security, legislatures, government IT, think tanks and universities, and civil-society and human-rights bodies.1 The intrusion typically began with spear-phishing that impersonated a trusted organization and recreated Gmail's attachment interface, followed by a five-stage infection chain culminating in DLL side-loading of Antino through a Microsoft-signed binary.1
The incident matters for two reasons beyond the victim list. First, the dead-drop-over-Microsoft-365 design collapses the distinction between malicious C2 and ordinary enterprise cloud traffic, defeating controls that key on unfamiliar destinations. Second, attribution is genuinely contested at the group level: Symantec, in research published August 13, 2026, attributes the Antino-related espionage to a named China-based APT it calls Jewelbug (aka Earth Alux, REF7707, CL-STA-0049) and ties it to a parallel cryptocurrency-fraud business, whereas Talos found overlaps but "could not independently verify a connection" and tracks UAT-11587 as a separate activity set.23
Verification of Claims
-
Claim: Antino uses Microsoft 365 (Outlook and OneDrive) via Graph as its C2. → Verified → Talos documents that Antino "communicates exclusively through Microsoft 365, using the Microsoft Graph API to interact with Outlook and OneDrive," authenticating via an OAuth 2.0 client-credentials flow, polling Outlook for commands every 10 seconds, and using OneDrive paths such as
/antino/heartbeats/{id}.jsonfor beaconing.1 -
Claim: The campaign compromised approximately 350 endpoints across eight countries. → Verified → Talos states: "Our investigation reveals approximately 350 compromised endpoints across eight countries," with the largest concentrated wave on June 8–9, 2026, when "around 57 newly observed endpoints associated with India" appeared. This endpoint count is a different denominator from the institution count.1
-
Claim: At least 16 institutional environments were affected or targeted. → Partially verified → Talos reports "at least 10 confirmed and five probable affected institutional environments, plus one additional intended target" — 16 in total, but only 10 are confirmed compromises. Characterizing all 16 as penetrated, as some coverage does, overstates the confirmed record.14
-
Claim: UAT-11587 is China-nexus. → Partially verified → Talos assesses this "with high confidence," expressly as a nexus judgment on "the totality of corroborating technical and operational evidence," not a claim of direct state tasking. Talos does not use the phrase "state-sponsored"; downstream coverage that does is inflating the stated confidence.15
-
Claim: UAT-11587 is the APT "Jewelbug." → Unverified → Symantec attributes the Antino-related espionage to a group it names Jewelbug; Talos "identified overlaps" but "could not independently verify a connection between the espionage campaign and Jewelbug's financially motivated activity" and tracks UAT-11587 separately.23
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| September–November 2025 | UAT-11587 | Earliest reviewed activity; Philippines-themed lures delivered via direct email attachment | 1 |
| October 2025 | UAT-11587 | Antino Gen1 builds observed | 1 |
| December 2025–January 2026 | UAT-11587 | Antino Gen2 build period (AntinoApp manifest, revised session-ID and heartbeat behavior) | 1 |
| January 2026 | UAT-11587 | Two further Philippines-focused HTA campaigns; standalone fake-installer delivery branch begins | 1 |
| March 2026 | UAT-11587 | Talos identifies the campaign while investigating spear-phishing against Taiwan's academic, think-tank and civil-society community; message recreated Gmail's attachment interface | 1 |
| March–early June 2026 | UAT-11587 | Activity accelerates across the Philippines and Taiwan, then Cambodia, Myanmar, Syria, Pakistan and Thailand | 1 |
| June 8–9, 2026 | UAT-11587 | Largest concentrated wave; ~57 newly observed endpoints associated with India | 1 |
| July 2026 | UAT-11587 | By this point ≥16 institutional environments across eight countries, ~350 endpoints | 1 |
| August 13, 2026 | Symantec | Publishes Jewelbug research attributing Antino espionage and parallel crypto fraud to one China-based group | 3 |
| September 30, 2026 | Cisco Talos | Publishes UAT-11587 / Antino report | 1 |
| October 2, 2026 | The Hacker News | Reports the campaign, keeping endpoint and institution counts distinct | 2 |
Attack Anatomy
Initial access and sender spoofing
Delivery began with spear-phishing. In the Taiwan operation, the message "recreated Gmail's attachment interface" using inline Base64-encoded PNG images, with the fake attachment card wrapped in an anchor pointing to an attacker-controlled Cloudflare Pages URL carrying an ?m= recipient identifier for per-target logging (T1566.002, T1204.001).1 Messages were sent through Migadu with the attacker-controlled osc-cdn[.]com domain as the RFC5321 envelope sender, while the RFC5322 From header displayed the impersonated organization's identity (T1684.001).1 SPF passed for the envelope domain; DMARC detected the misalignment and failed, but the displayed domain used a non-enforcing p=none policy, so the receiving provider still delivered the message.1 Earlier (September–November 2025) campaigns used direct email attachments instead (T1566.001).1
Stage 1 — HTA/WSF stager
The Cloudflare Pages link delivered an HTA file executed by mshta.exe (T1218.005). It "hides and resizes its window, emits a tracking request to an invariant Cloudflare Pages beacon, and imports the next JavaScript stage."1 A hidden image causes mshta.exe to request the fixed host oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev with the lure title in the path and ?track in the query, letting the operator correlate execution to a specific lure.1 Paired WSF variants achieve the same via Windows Script Host, sending an HTTP HEAD to the tracking host before loading the next stage.1
Stage 2 — JScript downloader and decryptor
HTA-hosted Microsoft JScript (T1059.007), delivered from Cloudflare R2 (pub-<32-hex>[.]r2[.]dev) or Amazon CloudFront (d2nq35tel3ucuo[.]cloudfront[.]net), retrieves three encrypted resources — an encrypted JScript orchestrator and two serialized .NET gadget resources — then decrypts and executes the orchestrator in memory to initiate a .NET 4.x deserialization chain (T1140).1
Stage 3 — .NET BinaryFormatter deserialization
The JScript instantiates COM-visible .NET classes and passes attacker-controlled serialized data into BinaryFormatter. The embedded gadget chain drives execution, loading and running an embedded .NET assembly, TestAssembly.dll, inside the script host process mshta.exe (T1620).1
Stage 4 — TestAssembly.dll downloader/launcher
TestAssembly.dll downloads a lure-specific decoy document and a three-file DLL-side-loading bundle from cloud infrastructure (T1105), opens the decoy for the victim (T1204.002), writes the bundle to a writable staging directory, and launches the Microsoft-signed GatherOsState.exe.1
Stage 5 — DLL side-loading of Antino
GatherOsState.exe, a legitimate Microsoft-signed Windows ADK binary, is abused to side-load slc.dll — the Antino backdoor (T1574.001).1 The staging directory observed was %LOCALAPPDATA%\Windows GatherOSStateKit\, and files were retrieved with randomized nonstandard extensions (e.g. .luy, .pzs, .syk).1
Command and control, discovery and exfiltration
Antino authenticates to Microsoft Graph via the OAuth 2.0 client-credentials flow of a registered Entra ID application (T1550.001), reaching only graph.microsoft.com and login.microsoftonline.com (T1071.001).1 It pulls tasking from an Outlook mailbox every 10 seconds using subjects command_req_[session_id] / command_res_[session_id], and uses OneDrive as a dead drop — /antino/heartbeats/{id}.json for check-ins, /antino_downloads/ for exfiltrated data, /antino_uploads/ for operator toolkit delivery (T1102.002, T1567.002).1 Backdoor commands cover reconnaissance (system_info, T1082; ps, T1057; list_files, T1083), execution (cmd via cmd.exe /C, T1059.003; powershell, T1059.001; execute_program; load_shellcode in memory, T1620), file transfer (upload_file, download_file), and persistence (add_to_run, a HKCU Run value, T1547.001).1 Configuration is stored in a custom .cfg PE section, XORed with the alternating key 0xAB 0xCD; an optional use_sleep_mask routine hooks Sleep and VirtualAlloc and uses a vectored exception handler to encrypt the payload region in memory between sleeps (T1027).1
Loading diagram...
Threat Actor Profile
Name: UAT-11587 (Cisco Talos intel-tracked cluster) Aliases: Overlaps with Symantec's Jewelbug (reported aliases Earth Alux, REF7707, CL-STA-0049); Talos tracks UAT-11587 as a separate activity set23 Attribution confidence: China-nexus, high confidence, per Cisco Talos, on "the totality of corroborating technical and operational evidence, rather than any single indicator"; intelligence-gathering purpose assessed at moderate confidence1 Motivation: Espionage / intelligence collection against government, defense, diplomatic and policy targets1
Talos named the malware after finding AntinoApp in its Windows application manifest and repeated antino directory names in PDB and Rust source paths (D:\a\antino\antino\...) across variants.1 Two generations were observed: Gen1 (October 2025) and Gen2 (December 2025–January 2026), differing in session-ID generation and heartbeat behavior, with Gen2 adding the AntinoApp manifest.1 The actor also distributed standalone Antino builds through fake installers at microsoft-flash[.]com and wps-cn[.]com (flashcenter_pp_ax_install_en.exe); the choice of wps-cn[.]com may indicate targeting of Chinese-speaking users.1 Symantec separately reports its Jewelbug cluster used additional implants (a Linux backdoor "ClientKing," a "PDF Viewer" browser extension) and held a victim database of more than one million implant check-in rows, 580,000+ browser cookies and 2,300+ exfiltrated email bodies across 15+ government webmail tenants — figures tied to Symantec's cluster, not independently confirmed by Talos for UAT-11587.3
MITRE ATT&CK techniques (IDs verified live on attack.mitre.org):
| ID | Technique |
|---|---|
| T1566.001 | Phishing: Spearphishing Attachment |
| T1566.002 | Phishing: Spearphishing Link |
| T1684.001 | Social Engineering: Impersonation |
| T1204.001 | User Execution: Malicious Link |
| T1204.002 | User Execution: Malicious File |
| T1218.005 | System Binary Proxy Execution: Mshta |
| T1059.007 | Command and Scripting Interpreter: JavaScript |
| T1059.001 | Command and Scripting Interpreter: PowerShell |
| T1059.003 | Command and Scripting Interpreter: Windows Command Shell |
| T1140 | Deobfuscate/Decode Files or Information |
| T1620 | Reflective Code Loading |
| T1574.001 | Hijack Execution Flow: DLL |
| T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
| T1550.001 | Use Alternate Authentication Material: Application Access Token |
| T1071.001 | Application Layer Protocol: Web Protocols |
| T1102.002 | Web Service: Bidirectional Communication |
| T1105 | Ingress Tool Transfer |
| T1082 | System Information Discovery |
| T1057 | Process Discovery |
| T1083 | File and Directory Discovery |
| T1567.002 | Exfiltration Over Web Service: Exfiltration to Cloud Storage |
| T1027 | Obfuscated Files or Information |
OPSEC: C2 confined to trusted Microsoft domains; staging inside Cloudflare Pages/R2 and CloudFront; per-recipient and per-lure execution tracking; randomized file extensions; in-memory assembly loading and optional sleep-mask memory encryption to evade scanners.1
Technical Indicators
actor_domains:
- osc-cdn[.]com # spear-phishing RFC5321 envelope-sender domain
- microsoft-flash[.]com # standalone fake-installer Antino delivery
- wps-cn[.]com # standalone fake-installer Antino delivery
execution_tracking:
- oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev # invariant Cloudflare Pages beacon (?track)
cloudflare_pages_delivery:
- my-3lyt6wcp[.]pages[.]dev
- my-qc39r814[.]pages[.]dev
- my-662ylt3w[.]pages[.]dev
- my-6g16qsfe[.]pages[.]dev
- my-goq6xmbm[.]pages[.]dev
- my-h3qli6kq[.]pages[.]dev
- my-sv7c1fzs[.]pages[.]dev
- my-u0up9qri[.]pages[.]dev
- my-vtsdod2n[.]pages[.]dev
- my-wgoxp32b[.]pages[.]dev
cloudflare_r2_staging:
- pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev
- pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev
cloudfront_staging:
- d2nq35tel3ucuo[.]cloudfront[.]net
ip_addresses:
- 103.27.110[.]220 # historical serving IP for wps-cn[.]com
standalone_delivery_urls:
- hxxps://microsoft-flash[.]com/download/flashcenter_pp_ax_install_en.exe
- hxxps://www[.]wps-cn[.]com/downloads/flashcenter_pp_ax_install_en.exe
antino_c2:
graph_endpoints:
- graph.microsoft[.]com
- login.microsoftonline[.]com
onedrive_paths:
- '/antino/heartbeats/{id}.json' # check-in
- '/antino_downloads/{file}' # exfiltration
- '/antino_uploads/{file}' # operator toolkit delivery
outlook_subjects:
- 'command_req_[session_id]'
- 'command_res_[session_id]'
poll_interval: every 10 seconds
host_artifacts:
staging_dir: '%LOCALAPPDATA%\Windows GatherOSStateKit\'
sideload_binary: 'GatherOsState.exe (Microsoft-signed Windows ADK, abused)'
sideloaded_dll: 'slc.dll (Antino)'
persistence: 'HKCU Run value (add_to_run command)'
config: 'custom .cfg PE section, XOR key 0xAB 0xCD'
assembly_guid: 'b2b3adb0-1669-4b94-86cb-6dd682ddbea3 (TestAssembly.dll)'
pdb_paths:
- 'D:\a\antino\antino\target\x86_64-pc-windows-msvc\release\deps\slc_template.pdb'
- 'D:\a\antino\antino\target\x86_64-pc-windows-msvc\release\deps\antino_client_template.pdb'
- 'D:\a\antino\antino\target\i686-pc-windows-msvc\release\deps\antino_client_template.pdb'
sha256_antino_samples:
- 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff # Gen2 slc.dll
- e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 # Gen2 slc.dll
- e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb # Gen2 slc.dll
- fdbd047031c13a17c9f491c9355f44d587584ebe2b8927be8482e6c236c8e1c1 # Gen2 slc.dll
- 1fadc90b61ce536abda78eb387a7f3d745f00c16775d3f762845ccc0fde567da # Gen1 slc.dll
- 40e7e77aff603f4c2ef17b3bc8ea836e714d0734a1e5b946e52f95536ec5c91d # Gen1 standalone
- 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd # Gen2 standalone
- 971cb2448b5d67dcc1f5eaa10d12e77f213035ad31230dc2ac7a510610a2059d # Gen2 standalone
- 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 # Gen2 standalone
- b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e # Gen2 standalone
- 5c5c060b272cd4a5c3767edc0e9478bd35b7e1756e183d0446a5491bd65519cb # standalone
- ca14ad0344dc7216f6da29a5cbe4237d886cc5257e8c3a48fb4885a311c9b800 # memory image
sha256_testassembly_downloaders:
- d753a615aedf8e58ffc75b2b7ebd320c0cbe6bcb5cbb885db749a2a85c55d3bf
- 133a46ba41136ca21c93fb08c28446826d8c0d9b7923a16f2d152d595a710098
- 9fc50cf28f86201fda8306926817b1ede41fdd993202515905dd072f6803542f
- d4cb2f5df16ec9b9c5b796ae55848534e15d4f8b8806f0431108fc7a99a2548a
- 131ac3e0df777910e0a32e43d5744bccb0490750d4c2adc359da41d76d383c46
note: >
Representative subset. Talos published fuller lists of HTA/WSF stagers, JScript
downloaders, encrypted orchestrators and BinaryFormatter gadget resources; see the
primary report for the complete IOC set. Network indicators are defanged.Legal and Regulatory Response
As of October 6, 2026, no law enforcement action, indictment, sanction, or government advisory tied specifically to UAT-11587 or the Antino backdoor had been published. The activity is documented in private-sector vendor research: Cisco Talos's report of September 30, 2026, and Symantec's Jewelbug research of August 13, 2026.13 No national CERT or agency advisory naming UAT-11587 or Antino was located as of that date.
Impact Assessment
- Confirmed: At least 10 confirmed affected institutional environments, with approximately 350 compromised endpoints across eight countries between September 2025 and July 2026, per Cisco Talos.1
- Confirmed: Antino's exclusive use of Microsoft 365 (Graph/Outlook/OneDrive) for C2, documented by Talos from recovered samples and developer artifacts.1
- Reported, not independently confirmed: Five probable affected environments and one additional intended target, raising the institution total to at least 16; targeting of organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria is assessed at moderate-to-high confidence.1
- Reported, not independently confirmed (separate cluster): Symantec's Jewelbug figures — 1M+ implant check-ins, 580,000+ cookies, 2,300+ exfiltrated emails across 15+ government webmail tenants — which Talos did not confirm for UAT-11587.3
- Unknown: The specific data exfiltrated from each victim, and whether UAT-11587 and Jewelbug are operated by the same entity.12
Lessons and Defensive Recommendations
For SOC/defenders:
- Treat Microsoft Graph traffic as a potential C2 channel: baseline and alert on OAuth client-credentials token grants to newly registered Entra ID apps, and on OneDrive/Outlook automation that does not map to an interactive user session.1
- Hunt for the dead-drop pattern — Outlook items with
command_req_/command_res_subjects and OneDrive paths under/antino/heartbeats/,/antino_downloads/,/antino_uploads/.1 - Alert on
mshta.exespawning script hosts and making outbound requests to*.pages.dev,*.r2.devorcloudfront.net, and onGatherOsState.exeexecuting from%LOCALAPPDATA%\Windows GatherOSStateKit\.1
For developers / platform teams:
- Audit signed binaries that load external libraries and restrict their DLL search paths;
GatherOsState.exeside-loadingslc.dllis the control that failed here.1 - Constrain or disable legacy
BinaryFormatterdeserialization in .NET surfaces reachable from script hosts.1
For cloud / email administrators:
- Move DMARC from
p=noneto enforcing (quarantine/reject); the spoof succeeded because the impersonated domain's policy only monitored.1 - Scope Entra ID application permissions tightly and review consent grants for Mail and Files access.1
For leadership:
- Assume adversaries will route C2 through the same SaaS platforms the organization trusts; detection investment should shift from blocking unfamiliar destinations to behavioral analytics on sanctioned cloud services.1
Sources
Footnotes
-
Cisco Talos — China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor — September 30, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34 ↩35 ↩36 ↩37 ↩38 ↩39 ↩40 ↩41 ↩42 ↩43 ↩44 ↩45 ↩46 ↩47 ↩48 ↩49 ↩50 ↩51 ↩52 ↩53 ↩54 ↩55 ↩56
-
The Hacker News — Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign — October 2, 2026 ↩ ↩2 ↩3 ↩4 ↩5
-
Symantec (Broadcom) — Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side — August 13, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
CybernewsAI — China's UAT-11587 Targets Asian Governments via Antino Backdoor — September 30, 2026 ↩
-
Security Online — UAT-11587 Targets Asian Governments With Antino Backdoor — October 2, 2026 ↩
Related Research
ESET Research documents SparroWocky, a new C++ backdoor from the China-aligned FamousSparrow APT that has almost exclusively targeted Latin American government organizations since mid-2025 — including an entity directly involved in Panama's contested port concession dispute.
Russia's FSB-linked Star Blizzard used a new delivery technique, RedFlick, in 13 phishing campaigns affecting 100+ US and UK organizations to deploy its CosmicPulse backdoor in 2026.
Rapid7's October 2, 2026 report details AVERAT and new BPFDoor/Rekoobe Linux implants that hide C2 in SMTP port 25 to mimic South Korean (SpamSniper) and Taiwanese (ShareTech) mail-security appliances and relay through compromised NAS, DVR and SMB devices against telecom targets.