China-Nexus Hackers Compromise 350 Systems Across Asia With New Antino Backdoor
Cisco Talos attributes UAT-11587 (China-nexus) to compromising ~350 endpoints in eight Asian countries using the Antino backdoor with Microsoft Graph-based C2.
Cisco Talos tracks China-nexus cluster UAT-11587 compromising roughly 350 endpoints across government, defense, diplomatic, academic and civil-society organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria between September 2025 and July 2026. Spear-phishing lures replicate Gmail's attachment-preview widget, deliver HTA/WSH stagers via mshta.exe, and load the Rust-based Antino backdoor through DLL sideloading with the Microsoft-signed GatherOsState.exe. Antino uses Microsoft Graph API with an Entra ID OAuth client-credentials flow to use attacker-controlled Outlook and OneDrive as dead-drop C2, uploading heartbeats to OneDrive every minute and polling an Outlook mailbox for commands every 10 seconds.
- ~350 endpoints compromised across eight Asian countries; 10 confirmed institutional victims
- Fake Gmail attachment-preview widgets deliver HTA/WSH stagers via Cloudflare Pages
- DLL sideloading via Microsoft-signed GatherOsState.exe loading malicious slc.dll
- C2 blends into Microsoft 365 traffic via Graph API, OneDrive uploads, Outlook dead-drop
- Talos released Snort rules 66880-66882, ClamAV signatures, and IOC repository
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | osc-cdn.com | sent mail through the Migadu service using their controlled osc-cdn[.]com domain as the SMTP envelope sender, while displaying an i |
Full article785 words · extracted from gbhackers.com · click to collapse
A China-nexus cyber-espionage campaign that compromised approximately 350 endpoints across Asia using a previously undocumented Rust-based Windows backdoor called Antino.
The activity cluster, tracked as UAT-11587, targeted government, defense, diplomatic, policy, academic and civil-society organizations in at least eight countries between September 2025 and July 2026.
Talos identified 10 confirmed and five probable affected institutional environments, alongside one additional intended target.
Victims and targets were located in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria, with organizations involved in national security, foreign affairs, law enforcement, legislatures, e-government services, think tanks and universities particularly exposed.
The largest recorded wave occurred on June 8 and 9, 2026, when researchers observed about 57 newly identified endpoints associated with India.
UAT-11587 used highly tailored lures based on regional political developments, government administration, maritime policy, human rights, cross-strait issues and diplomatic events.
In one technique, the actor reproduced Gmail’s attachment-preview widget inside email HTML, creating a clickable attachment card designed to appear legitimate to recipients.
The phishing messages abused sender-domain misalignment to impersonate trusted entities.
The attackers sent mail through the Migadu service using their controlled osc-cdn[.]com domain as the SMTP envelope sender, while displaying an impersonated organization in the visible From field.
Although SPF passed for the attacker-controlled domain, DMARC alignment failed. Because the spoofed sender’s domain used a non-enforcing p=none policy, the message was still delivered to the victim’s inbox.
The attack chain begins when a recipient opens a malicious Cloudflare Pages link embedded in the fake attachment interface.

The link delivers an HTA or Windows Script Host stager that runs through mshta.exe or WSH, records execution telemetry and retrieves subsequent payloads from Cloudflare R2 or Amazon CloudFront.
A second-stage JScript downloader retrieves encrypted resources, applies custom Base64 decoding and RC4 decryption, then executes an in-memory .NET deserialization sequence.
Antino Backdoor
The attackers abuse BinaryFormatter and standard .NET gadget chains to load TestAssembly.dll directly inside the mshta.exe process.
Cisco Talos observed that, the campaign surfaced during an investigation into spear-phishing operations against Taiwan’s academic, think-tank and civil-society policy communities.
The actor replicated the styling of Gmail’s attachment card using four inline PNG images embedded as Base64-encoded MIME parts.

The .NET component retrieves a decoy document and a DLL-sideloading bundle.
It launches the legitimate Microsoft-signed Windows ADK binary GatherOsState.exe, which sideloads a malicious adjacent slc.dll file containing Antino.
This use of a signed Windows binary reduces suspicion and can complicate endpoint detection.
Antino is available as both a standalone executable and DLL, with 32-bit and 64-bit builds.
It provides host reconnaissance, command-shell and PowerShell execution, directory enumeration, file upload and download, in-memory shellcode loading, and Registry Run-key persistence.

Its most notable feature is its command-and-control architecture. Rather than communicate with a conventional external C2 server, Antino uses Microsoft Graph API calls to interact exclusively with attacker-controlled Outlook and OneDrive resources.
The malware authenticates through an Entra ID application using the OAuth 2.0 client-credentials flow, allowing it to communicate through trusted Microsoft 365 services without an interactive login.
The implant uploads heartbeat telemetry to OneDrive every minute, including the machine name, username, platform, session identifier and campaign information.
It also uses OneDrive folders to receive tools and upload stolen data. For tasking, Antino polls an Outlook mailbox every 10 seconds for messages named command_req_[session_id] and sends results through corresponding command_res_[session_id] messages.
This dead-drop model allows malicious traffic to blend with ordinary Microsoft 365 synchronization activity directed to graph.microsoft.com and login.microsoftonline.com, making network-only detection substantially harder.
Talos assessed with high confidence that UAT-11587 is China-nexus based on converging operational and technical indicators.
These include Simplified Chinese metadata in Taiwan-focused decoys, UTC+8 timestamps, repeated references to the mainland China-focused Rust package mirror rsproxy.cn, and victimology consistent with regional intelligence collection.
Talos also found limited infrastructure overlap with activity previously associated with China-nexus UNC6384, although it rated that connection as low confidence.
Defenders should investigate unusual mshta.exe or WSH activity reaching Cloudflare Pages, R2 or CloudFront; Microsoft-signed GatherOsState.exe instances loading locally placed slc.dll; suspicious Graph API activity involving unfamiliar Entra applications; and OneDrive paths resembling /antino/heartbeats/, /antino_uploads/ or /antino_downloads/.
Talos released ClamAV signatures and Snort rules 66880–66882 for detection, while its published IOC repository contains hashes for malicious HTA, WSF, JScript and serialized loader components.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.