Threat reportAPTTL-2026-2848

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)

highACTIVE

Antino Backdoor Uses Outlook and OneDrive for C2 in (TL-2026-2848) is a high-severity advanced persistent threat campaign, first published 2026-10-02 and last reviewed 2026-10-03. It is attributed to UAT-11587 (China) with high confidence, affects Microsoft Windows (endpoints; abuse of Microsoft Graph, Outlook, maps to 24 MITRE ATT&CK techniques (T1027, T1057, T1059.001), and is covered by 9 detection rules and 36 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
1UAT-11587
Detection rules
9SPL · KQL · Sigma
IOCs
36Indicators of compromise

Key facts for TL-2026-2848

Threat ID
TL-2026-2848
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
UAT-11587
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, defense, diplomatic, police - law enforcement, legislative, think tanks, academia, civil society
Target regions
taiwan, india, philippines, cambodia, pakistan, thailand, myanmar, syria
Detection rules
9
Indicators of compromise
36
Updates
2026-10-03 · revalidated 1× · latest source

Malware and tooling in Antino Backdoor Uses Outlook and OneDrive for C2 in

Malware and tooling: Antino

How Antino Backdoor Uses Outlook and OneDrive for C2 in works

Cisco Talos tracks UAT-11587, a China-nexus (high confidence) cluster that has deployed the Rust-based Antino backdoor against government, defense, policy and academic organizations across eight Asian countries since September 2025. Antino uses Microsoft Graph to dead-drop C2 through Outlook (commands) and OneDrive (heartbeats, tools, exfiltration), delivered by a five-stage chain starting from spoofed spear-phishing.

Cisco Talos assesses with high confidence that UAT-11587 is a China-nexus cluster active from September 2025 through July 2026. By July 2026 Talos had identified at least 16 affected institutions across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria; secondary reporting cites approximately 350 compromised endpoints. Targeted sectors include defense and national security, executive government, foreign affairs/diplomatic services, justice and law enforcement, legislative institutions, government IT, think tanks, universities and civil-society groups. Activity accelerated March-June 2026, with roughly 57 new endpoints observed in India on June 8-9, 2026.

Initial access is spear-phishing. Operators spoof a trusted organization in the RFC5322 From header while the SMTP envelope sender is the attacker-controlled domain osc-cdn.com (SPF passes via Migadu; DMARC fails but is accepted because the impersonated domain publishes p=none). Some lures reproduce Gmail's native attachment-preview widget inside the HTML body using four inline Base64 PNG images wrapped in an anchor to an attacker Cloudflare Pages URL of the form my-<project>.pages.dev/File_download?m=<target-identifier>, which gives per-recipient tracking. Earlier waves (Sep-Nov 2025) delivered attachments directly with Philippines-themed content. Decoys include a Taiwan information-warfare workshop document, a Taiwan Ministry of Finance legislative tax ruling and a CSIS Indo-Pacific 2026 forecast; other recovered lure filenames reference Bajo de Masinloc, cross-border repression, a Tehran bilateral summit and an Indian cabinet-meeting item (.doc.exe).

The infection chain has five stages. (1) An HTA or WSF stager executed via mshta.exe/Windows Script Host contacts Cloudflare Pages. (2) A JScript downloader retrieves three encrypted resources from Cloudflare R2 or Amazon CloudFront, decrypting them with RC4 and a custom Base64 decoder. (3) A .NET BinaryFormatter deserialization chain (System.Windows.Forms.AxHost+State gadget with ActivitySurrogateSelector) loads TestAssembly.dll into mshta.exe memory. (4) TestAssembly.dll downloads a lure-specific decoy plus a three-file sideloading bundle. (5) The legitimate Microsoft ADK binary GatherOsState.exe sideloads the malicious slc.dll (Antino) and calls its SLOpen export.

Antino is a Rust-compiled Windows backdoor (PE manifest AntinoApp in Gen2, custom .cfg section holding XOR-encrypted JSON config with alternating key 0xAB 0xCD). It supports cmd, powershell, system_info, execute_program, list_files, upload_file, download_file, load_shellcode, add_to_run (HKCU Run persistence) and exit. C2 runs entirely over Microsoft Graph: the implant polls an attacker-controlled Outlook mailbox every 10 seconds for messages with subject command_req_[session_id] and replies with command_res_[session_id] (JSON body: command_type, command_data, request_id); OneDrive handles registration/heartbeats (/antino/heartbeats/{id}.json, roughly every minute), tool delivery (/antino_uploads/) and exfiltration (/antino_downloads/). Gen1 (Oct 2025) used email drafts for heartbeats and XOR/Base64 hostname-derived session IDs; Gen2 (Dec 2025-Jan 2026) moved heartbeats to OneDrive JSON and random UUIDv4 session IDs. Shellcode is protected with a Sleep hook that flips VirtualAlloc regions to PAGE_READWRITE and XOR-encrypts them during sleep, restored via a vectored exception handler. The actor also abuses Windows Scripted Diagnostics (CScriptedDiag CLSID {1F3D8AA5-9EBF-4EE4-85C2-EA40379AEDE8} from sdiageng.dll, Program Compatibility Wizard package C:\Windows\diagnostics\system\PCW) so that sdiagnhost.exe runs attacker-controlled PowerShell.

Attribution rests on decoy metadata (zh-CN language tag, Simplified Chinese author value 未定义, +08:00 creation timestamps), ten Antino builds referencing the mainland-China Rust mirror rsproxy.cn, and CloudFront infrastructure (d32tpl7xt7175h.cloudfront.net) shared with reported China-nexus UNC6384. Talos notes some overlap with Jewelbug (Symantec) but designates UAT-11587 a separate cluster because of different core malware and C2 architecture, and found no connection to Jewelbug's financially motivated activity. Single primary source: Cisco Talos; no CVE is involved.

MITRE ATT&CK techniques used in TL-2026-2848

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1202 Indirect Command Execution; T1218.005 Mshta; T1574.001 DLL; T1620 Reflective Code Loading; T1684.001 Impersonation

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.007 JavaScript; T1204.002 Malicious File

Command and Control

T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer

Persistence

T1547.001 Registry Run Keys / Startup Folder; T1574.002 DLL Side-Loading

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Exfiltration

T1567.002 Exfiltration to Cloud Storage

Resource Development

T1583.001 Domains; T1583.006 Web Services; T1608.001 Upload Malware

Affected products and versions in Antino Backdoor Uses Outlook and OneDrive for C2 in

  • Microsoft — Windows (endpoints; abuse of Microsoft Graph, Outlook, OneDrive, mshta.exe, GatherOsState.exe, Scripted Diagnostics)

Remediation for Antino Backdoor Uses Outlook and OneDrive for C2 in

Immediate actions

  • Hunt for mshta.exe or wscript.exe retrieving content from *.pages.dev, *.r2.dev or *.cloudfront.net
  • Hunt for GatherOsState.exe running from user-writable directories and loading slc.dll
  • Alert on sdiagnhost.exe spawning PowerShell or followed by HKCU Run key changes
  • Block osc-cdn.com, microsoft-flash.com, wps-cn.com and the listed R2/CloudFront/Pages hosts
  • Review Microsoft Graph activity (graph.microsoft.com, login.microsoftonline.com) correlated with suspicious process execution

Workarounds

  • Apply Cisco Talos ClamAV signatures (Html.Trojan.UAT-11587, Win.Trojan.UAT-11587, Txt.Trojan.UAT-11587) and Snort rules 1:66880, 1:66881, 1:66882

Longer-term hardening

  • Enforce DMARC reject on owned domains and flag mail where envelope sender and From domain differ
  • Restrict or disable HTA/WSF execution (mshta.exe, wscript.exe) for standard users
  • Apply Entra/Conditional Access controls and monitor for unmanaged-tenant Graph API use from endpoints
  • Deploy EDR with behavioral coverage of DLL sideloading and in-memory shellcode

Timeline of Antino Backdoor Uses Outlook and OneDrive for C2 in

  • Earliest UAT-11587 / Antino activity observed by Cisco Talos (Sep-Nov 2025: Philippines-themed emails with direct attachments)
  • Antino Gen1 builds (no manifest; heartbeats via email drafts; XOR/Base64 hostname session IDs) observed from October 2025
  • Antino Gen2 builds (AntinoApp manifest, UUIDv4 session IDs, OneDrive JSON heartbeats) appear, Dec 2025-Jan 2026
  • Philippines HTA campaigns and broader policy/geopolitical lures begin in January 2026
  • Operations accelerate March-June 2026 across the Philippines, Taiwan, Cambodia, Myanmar, Syria, Pakistan and Thailand
  • Cloudflare Pages-hosted HTA lures dated May 2026 in circulation (e.g. Institutional_Disciplinary_Action_Report_May_2026.hta, Tehran_Bilateral_Summit_Proceedings_May2026.hta, Internal_Review_Dossier_0520.hta).
  • Spike of roughly 57 new compromised endpoints in India on June 8-9, 2026
  • By July 2026 Talos identifies at least 16 affected institutions in eight countries (about 350 endpoints per secondary reporting)
  • Cisco Talos research on UAT-11587 and Antino publicly reported; The Hacker News coverage published

Update history for TL-2026-2848

Sources cited for Antino Backdoor Uses Outlook and OneDrive for C2 in

Detection coverage for TL-2026-2848

As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2848 across Splunk SPL, Microsoft KQL and Sigma, covering 36 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
36 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2848

3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats