Talos Links Antino Backdoor to China-Nexus UAT-11587
Cisco Talos says China-linked UAT-11587 used the Antino Rust backdoor and Microsoft 365 to spy on Asian governments.
Cisco Talos says the China-nexus cluster it tracks as UAT-11587 deployed a previously undocumented Rust Windows backdoor called Antino against government and policy organizations. One report says the espionage campaign has run since September 2025 and, by July 2026, compromised about 350 endpoints at 16 organizations across eight Asian countries, including a wave of about 57 endpoints in India over two days in June. The other report does not give those totals and instead names Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, plus a later target in Syria. Antino supports 32-bit and 64-bit Windows and uses Microsoft Graph so Outlook serves as dead-drop command and control, polled about every 10 seconds in one account, while OneDrive stages stolen files; reported functions include reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode, and persistence. Delivery begins with spoofed spear-phishing and a fake Gmail attachment card leading to HTA or Windows Script Host stagers, with one report also citing a .NET deserialization gadget before DLL sideloading through the signed Microsoft binary GatherOsState.exe. Talos points to Simplified Chinese metadata, UTC+8 timestamps, and a mainland China Rust package mirror, notes overlap with Jewelbug and related clusters, and tracks this activity separately.
- Cisco Talos attributes the Antino campaign to China-nexus cluster UAT-11587 and tracks it separately from Jewelbug despite noted overlap.
- Antino is a previously undocumented Rust backdoor for 32-bit and 64-bit Windows that uses Microsoft Graph, with Outlook as a dead-drop command channel polled about every 10 seconds and OneDrive to stage stolen files.
- Reported capabilities include reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode, and persistence.
- One report says the campaign began in September 2025 and, by July 2026, had compromised about 350 endpoints at 16 government and policy organizations across eight Asian countries.
- The other report names government and policy targets in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, and describes Syria as a later target.
- The largest reported wave hit about 57 endpoints in India over two days in June.
- Access used spear-phishing that spoofed trusted senders and a fake Gmail attachment card, followed by HTA or Windows Script Host stagers; one account also cites a .NET deserialization gadget and both describe DLL sideloading via signed…
- Talos cites Simplified Chinese metadata, UTC+8 timestamps, and a mainland China Rust package mirror.
Coverage timelineoldest first · each row is one article
- · 6d agoAntino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
The Hacker News· 78
Cisco Talos says China-nexus UAT-11587 deployed the Antino backdoor against Asian government and policy organizations.
- · 5d agoAntino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel
Security Affairs· 78
China-linked UAT-11587 used the Antino backdoor and Microsoft 365 to spy on Asian governments.