Threat reportAPTTL-2026-2848
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)
Antino Backdoor Uses Outlook and OneDrive for C2 in (TL-2026-2848) is a high-severity advanced persistent threat campaign, first published 2026-10-02 and last reviewed 2026-10-03. It is attributed to UAT-11587 (China) with high confidence, affects Microsoft Windows (endpoints; abuse of Microsoft Graph, Outlook, maps to 24 MITRE ATT&CK techniques (T1027, T1057, T1059.001), and is covered by 9 detection rules and 36 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 24MITRE ATT&CK
- Actors
- 1UAT-11587
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 36Indicators of compromise
Key facts for TL-2026-2848
- Threat ID
- TL-2026-2848
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- UAT-11587
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government administration, defense, diplomatic, police - law enforcement, legislative, think tanks, academia, civil society
- Target regions
- taiwan, india, philippines, cambodia, pakistan, thailand, myanmar, syria
- Detection rules
- 9
- Indicators of compromise
- 36
- Updates
- 2026-10-03 · revalidated 1× · latest source
Malware and tooling in Antino Backdoor Uses Outlook and OneDrive for C2 in
Malware and tooling: Antino
How Antino Backdoor Uses Outlook and OneDrive for C2 in works
Cisco Talos tracks UAT-11587, a China-nexus (high confidence) cluster that has deployed the Rust-based Antino backdoor against government, defense, policy and academic organizations across eight Asian countries since September 2025. Antino uses Microsoft Graph to dead-drop C2 through Outlook (commands) and OneDrive (heartbeats, tools, exfiltration), delivered by a five-stage chain starting from spoofed spear-phishing.
Cisco Talos assesses with high confidence that UAT-11587 is a China-nexus cluster active from September 2025 through July 2026. By July 2026 Talos had identified at least 16 affected institutions across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria; secondary reporting cites approximately 350 compromised endpoints. Targeted sectors include defense and national security, executive government, foreign affairs/diplomatic services, justice and law enforcement, legislative institutions, government IT, think tanks, universities and civil-society groups. Activity accelerated March-June 2026, with roughly 57 new endpoints observed in India on June 8-9, 2026.
Initial access is spear-phishing. Operators spoof a trusted organization in the RFC5322 From header while the SMTP envelope sender is the attacker-controlled domain osc-cdn.com (SPF passes via Migadu; DMARC fails but is accepted because the impersonated domain publishes p=none). Some lures reproduce Gmail's native attachment-preview widget inside the HTML body using four inline Base64 PNG images wrapped in an anchor to an attacker Cloudflare Pages URL of the form my-<project>.pages.dev/File_download?m=<target-identifier>, which gives per-recipient tracking. Earlier waves (Sep-Nov 2025) delivered attachments directly with Philippines-themed content. Decoys include a Taiwan information-warfare workshop document, a Taiwan Ministry of Finance legislative tax ruling and a CSIS Indo-Pacific 2026 forecast; other recovered lure filenames reference Bajo de Masinloc, cross-border repression, a Tehran bilateral summit and an Indian cabinet-meeting item (.doc.exe).
The infection chain has five stages. (1) An HTA or WSF stager executed via mshta.exe/Windows Script Host contacts Cloudflare Pages. (2) A JScript downloader retrieves three encrypted resources from Cloudflare R2 or Amazon CloudFront, decrypting them with RC4 and a custom Base64 decoder. (3) A .NET BinaryFormatter deserialization chain (System.Windows.Forms.AxHost+State gadget with ActivitySurrogateSelector) loads TestAssembly.dll into mshta.exe memory. (4) TestAssembly.dll downloads a lure-specific decoy plus a three-file sideloading bundle. (5) The legitimate Microsoft ADK binary GatherOsState.exe sideloads the malicious slc.dll (Antino) and calls its SLOpen export.
Antino is a Rust-compiled Windows backdoor (PE manifest AntinoApp in Gen2, custom .cfg section holding XOR-encrypted JSON config with alternating key 0xAB 0xCD). It supports cmd, powershell, system_info, execute_program, list_files, upload_file, download_file, load_shellcode, add_to_run (HKCU Run persistence) and exit. C2 runs entirely over Microsoft Graph: the implant polls an attacker-controlled Outlook mailbox every 10 seconds for messages with subject command_req_[session_id] and replies with command_res_[session_id] (JSON body: command_type, command_data, request_id); OneDrive handles registration/heartbeats (/antino/heartbeats/{id}.json, roughly every minute), tool delivery (/antino_uploads/) and exfiltration (/antino_downloads/). Gen1 (Oct 2025) used email drafts for heartbeats and XOR/Base64 hostname-derived session IDs; Gen2 (Dec 2025-Jan 2026) moved heartbeats to OneDrive JSON and random UUIDv4 session IDs. Shellcode is protected with a Sleep hook that flips VirtualAlloc regions to PAGE_READWRITE and XOR-encrypts them during sleep, restored via a vectored exception handler. The actor also abuses Windows Scripted Diagnostics (CScriptedDiag CLSID {1F3D8AA5-9EBF-4EE4-85C2-EA40379AEDE8} from sdiageng.dll, Program Compatibility Wizard package C:\Windows\diagnostics\system\PCW) so that sdiagnhost.exe runs attacker-controlled PowerShell.
Attribution rests on decoy metadata (zh-CN language tag, Simplified Chinese author value 未定义, +08:00 creation timestamps), ten Antino builds referencing the mainland-China Rust mirror rsproxy.cn, and CloudFront infrastructure (d32tpl7xt7175h.cloudfront.net) shared with reported China-nexus UNC6384. Talos notes some overlap with Jewelbug (Symantec) but designates UAT-11587 a separate cluster because of different core malware and C2 architecture, and found no connection to Jewelbug's financially motivated activity. Single primary source: Cisco Talos; no CVE is involved.
MITRE ATT&CK techniques used in TL-2026-2848
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1202 Indirect Command Execution; T1218.005 Mshta; T1574.001 DLL; T1620 Reflective Code Loading; T1684.001 Impersonation
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.007 JavaScript; T1204.002 Malicious File
Command and Control
T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer
Persistence
T1547.001 Registry Run Keys / Startup Folder; T1574.002 DLL Side-Loading
Initial Access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Exfiltration
T1567.002 Exfiltration to Cloud Storage
Resource Development
T1583.001 Domains; T1583.006 Web Services; T1608.001 Upload Malware
Affected products and versions in Antino Backdoor Uses Outlook and OneDrive for C2 in
- Microsoft — Windows (endpoints; abuse of Microsoft Graph, Outlook, OneDrive, mshta.exe, GatherOsState.exe, Scripted Diagnostics)
Remediation for Antino Backdoor Uses Outlook and OneDrive for C2 in
Immediate actions
- Hunt for mshta.exe or wscript.exe retrieving content from *.pages.dev, *.r2.dev or *.cloudfront.net
- Hunt for GatherOsState.exe running from user-writable directories and loading slc.dll
- Alert on sdiagnhost.exe spawning PowerShell or followed by HKCU Run key changes
- Block osc-cdn.com, microsoft-flash.com, wps-cn.com and the listed R2/CloudFront/Pages hosts
- Review Microsoft Graph activity (graph.microsoft.com, login.microsoftonline.com) correlated with suspicious process execution
Workarounds
- Apply Cisco Talos ClamAV signatures (Html.Trojan.UAT-11587, Win.Trojan.UAT-11587, Txt.Trojan.UAT-11587) and Snort rules 1:66880, 1:66881, 1:66882
Longer-term hardening
- Enforce DMARC reject on owned domains and flag mail where envelope sender and From domain differ
- Restrict or disable HTA/WSF execution (mshta.exe, wscript.exe) for standard users
- Apply Entra/Conditional Access controls and monitor for unmanaged-tenant Graph API use from endpoints
- Deploy EDR with behavioral coverage of DLL sideloading and in-memory shellcode
Timeline of Antino Backdoor Uses Outlook and OneDrive for C2 in
- Earliest UAT-11587 / Antino activity observed by Cisco Talos (Sep-Nov 2025: Philippines-themed emails with direct attachments)
- Antino Gen1 builds (no manifest; heartbeats via email drafts; XOR/Base64 hostname session IDs) observed from October 2025
- Antino Gen2 builds (AntinoApp manifest, UUIDv4 session IDs, OneDrive JSON heartbeats) appear, Dec 2025-Jan 2026
- Philippines HTA campaigns and broader policy/geopolitical lures begin in January 2026
- Operations accelerate March-June 2026 across the Philippines, Taiwan, Cambodia, Myanmar, Syria, Pakistan and Thailand
- Cloudflare Pages-hosted HTA lures dated May 2026 in circulation (e.g. Institutional_Disciplinary_Action_Report_May_2026.hta, Tehran_Bilateral_Summit_Proceedings_May2026.hta, Internal_Review_Dossier_0520.hta).
- Spike of roughly 57 new compromised endpoints in India on June 8-9, 2026
- By July 2026 Talos identifies at least 16 affected institutions in eight countries (about 350 endpoints per secondary reporting)
- Cisco Talos research on UAT-11587 and Antino publicly reported; The Hacker News coverage published
Update history for TL-2026-2848
- 2026-10-03 — Antino Backdoor: China-Linked UAT-11587 Uses Microsoft 365 (Graph API / Outlook) as C2 Against Asian Government Targets: What changed No severity, exploitability or attribution change; additive enrichment only. New indicators (9) 3 additional Cloudflare Pages HTA delivery hosts, a second standalone-installer URL (wps-cn.com), the R2-hosted slc.dll.pzs payload
Sources cited for Antino Backdoor Uses Outlook and OneDrive for C2 in
- Cisco Talos: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
- The Hacker News: Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
- eSecurity Planet: China-Linked Hackers Use Antino Backdoor in Asia
- SOC Prime: UAT-11587 Deploys Antino Backdoor in Asia
- Cyberpress: China-Nexus UAT-11587 Compromises 350 Endpoints Across Eight Countries
- SecurityOnline: UAT-11587 Targets Asian Governments With Antino Backdoor
Detection coverage for TL-2026-2848
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2848 across Splunk SPL, Microsoft KQL and Sigma, covering 36 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2848
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.