China-nexus UAT-11587 deploys Antino backdoor across Asia
Cisco Talos says China-nexus UAT-11587 used the Rust Antino backdoor to compromise about 350 endpoints across eight Asian countries.
Cisco Talos attributes China-nexus cluster UAT-11587, first observed in September 2025 and active through July 2026, to espionage against government, policy, defense, diplomatic, academic, and civil-society organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria, which The Hacker News says was targeted later. The actor deploys Antino, a previously undocumented Rust Windows backdoor for host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading, and persistence, with command-and-control only through Microsoft Graph: an Entra ID OAuth client-credentials flow uses attacker-controlled Outlook and OneDrive as dead drops, uploading heartbeats every minute and polling Outlook every 10 seconds. Initial access is spear-phishing that spoofs trusted senders and fakes Gmail’s attachment-preview card, then HTA/WSH or WSF stagers via mshta.exe—sources differ on the script type—a five-stage chain, Cloudflare infrastructure including Cloudflare Pages, and DLL sideloading of malicious slc.dll through Microsoft-signed GatherOsState.exe. By July 2026 Talos reported at least 16 affected or targeted institutional environments and about 350 compromised endpoints across eight countries; GBHackers cites 10 confirmed institutional victims, a lower figure. Attribution rests on zh-CN metadata, UTC+8 timestamps, and rsproxy.cn build artifacts; Talos notes low-confidence overlap with Symantec’s Jewelbug and UNC6384 but tracks UAT-11587 separately, and published Snort rules 66880-66882, ClamAV signatures, and an IOC repository.
- Cisco Talos tracks China-nexus cluster UAT-11587, first observed in September 2025 and active through July 2026.
- Antino is a previously undocumented Rust-compiled Windows backdoor supporting reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading, and persistence.
- C2 uses only Microsoft Graph with an Entra ID OAuth client-credentials flow: OneDrive heartbeats every minute and Outlook mailbox polling every 10 seconds as dead drops.
- About 350 endpoints were compromised across eight countries: Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria (The Hacker News says Syria came later).
- Talos reports at least 16 affected or targeted institutional environments; GBHackers reports 10 confirmed institutional victims.
- Access used spear-phishing that spoofed trusted senders and fake Gmail attachment-preview cards, HTA/WSH or WSF stagers via mshta.exe, a five-stage chain, Cloudflare Pages, and DLL sideloading of slc.dll through signed GatherOsState.exe.
- China-nexus attribution cites zh-CN metadata, UTC+8 timestamps, and rsproxy.cn build artifacts; low-confidence overlap with Jewelbug and UNC6384, tracked separately.
- Talos released Snort rules 66880-66882, ClamAV signatures, and an IOC repository.
Coverage timelineoldest first · each row is one article
- · 2d agoChina-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos· 75
Cisco Talos attributes China-nexus UAT-11587 to espionage against Asian governments using the Rust-based Antino backdoor, with ~350 compromised endpoints in eight countries.
- · 1d agoChina-Nexus Hackers Compromise 350 Systems Across Asia With New Antino Backdoor
GBHackers· 72
Cisco Talos attributes UAT-11587 (China-nexus) to compromising ~350 endpoints in eight Asian countries using the Antino backdoor with Microsoft Graph-based C2.
- · 3h ago