# Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)

> Cisco Talos tracks UAT-11587, a China-nexus (high confidence) cluster that has deployed the Rust-based Antino backdoor against government, defense, policy and academic organizations across eight Asian countries since September 2025. Antino uses Microsoft Graph to dead-drop C2 through Outlook (commands) and OneDrive (heartbeats, tools, exfiltration), delivered by a five-stage chain starting from spoofed spear-phishing.

- **Published:** 2026-10-02T00:00:00Z
- **Last reviewed:** 2026-10-03T13:51:04.190Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2848
- **ID:** TL-2026-2848
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** UAT-11587 (China)
- **Detections:** 9 · **IOCs:** 36 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Cisco Talos assesses with high confidence that UAT-11587 is a China-nexus cluster active from September 2025 through July 2026. By July 2026 Talos had identified at least 16 affected institutions across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria; secondary reporting cites approximately 350 compromised endpoints. Targeted sectors include defense and national security, executive government, foreign affairs/diplomatic services, justice and law enforcement, legislative institutions, government IT, think tanks, universities and civil-society groups. Activity accelerated March-June 2026, with roughly 57 new endpoints observed in India on June 8-9, 2026.

Initial access is spear-phishing. Operators spoof a trusted organization in the RFC5322 From header while the SMTP envelope sender is the attacker-controlled domain osc-cdn.com (SPF passes via Migadu; DMARC fails but is accepted because the impersonated domain publishes p=none). Some lures reproduce Gmail's native attachment-preview widget inside the HTML body using four inline Base64 PNG images wrapped in an anchor to an attacker Cloudflare Pages URL of the form my-<project>.pages.dev/File_download?m=<target-identifier>, which gives per-recipient tracking. Earlier waves (Sep-Nov 2025) delivered attachments directly with Philippines-themed content. Decoys include a Taiwan information-warfare workshop document, a Taiwan Ministry of Finance legislative tax ruling and a CSIS Indo-Pacific 2026 forecast; other recovered lure filenames reference Bajo de Masinloc, cross-border repression, a Tehran bilateral summit and an Indian cabinet-meeting item (.doc.exe).

The infection chain has five stages. (1) An HTA or WSF stager executed via mshta.exe/Windows Script Host contacts Cloudflare Pages. (2) A JScript downloader retrieves three encrypted resources from Cloudflare R2 or Amazon CloudFront, decrypting them with RC4 and a custom Base64 decoder. (3) A .NET BinaryFormatter deserialization chain (System.Windows.Forms.AxHost+State gadget with ActivitySurrogateSelector) loads TestAssembly.dll into mshta.exe memory. (4) TestAssembly.dll downloads a lure-specific decoy plus a three-file sideloading bundle. (5) The legitimate Microsoft ADK binary GatherOsState.exe sideloads the malicious slc.dll (Antino) and calls its SLOpen export.

Antino is a Rust-compiled Windows backdoor (PE manifest AntinoApp in Gen2, custom .cfg section holding XOR-encrypted JSON config with alternating key 0xAB 0xCD). It supports cmd, powershell, system_info, execute_program, list_files, upload_file, download_file, load_shellcode, add_to_run (HKCU Run persistence) and exit. C2 runs entirely over Microsoft Graph: the implant polls an attacker-controlled Outlook mailbox every 10 seconds for messages with subject command_req_[session_id] and replies with command_res_[session_id] (JSON body: command_type, command_data, request_id); OneDrive handles registration/heartbeats (/antino/heartbeats/{id}.json, roughly every minute), tool delivery (/antino_uploads/) and exfiltration (/antino_downloads/). Gen1 (Oct 2025) used email drafts for heartbeats and XOR/Base64 hostname-derived session IDs; Gen2 (Dec 2025-Jan 2026) moved heartbeats to OneDrive JSON and random UUIDv4 session IDs. Shellcode is protected with a Sleep hook that flips VirtualAlloc regions to PAGE_READWRITE and XOR-encrypts them during sleep, restored via a vectored exception handler. The actor also abuses Windows Scripted Diagnostics (CScriptedDiag CLSID {1F3D8AA5-9EBF-4EE4-85C2-EA40379AEDE8} from sdiageng.dll, Program Compatibility Wizard package C:\Windows\diagnostics\system\PCW) so that sdiagnhost.exe runs attacker-controlled PowerShell.

Attribution rests on decoy metadata (zh-CN language tag, Simplified Chinese author value 未定义, +08:00 creation timestamps), ten Antino builds referencing the mainland-China Rust mirror rsproxy.cn, and CloudFront infrastructure (d32tpl7xt7175h.cloudfront.net) shared with reported China-nexus UNC6384. Talos notes some overlap with Jewelbug (Symantec) but designates UAT-11587 a separate cluster because of different core malware and C2 architecture, and found no connection to Jewelbug's financially motivated activity. Single primary source: Cisco Talos; no CVE is involved.

## MITRE ATT&CK

- T1583.001 Domains
- T1583.006 Web Services
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1204.002 Malicious File
- T1059.007 JavaScript
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1547.001 Registry Run Keys / Startup Folder
- T1218.005 Mshta
- T1574.001 DLL
- T1620 Reflective Code Loading
- T1140 Deobfuscate/Decode Files or Information
- T1202 Indirect Command Execution
- T1684.001 Impersonation
- T1082 System Information Discovery
- T1057 Process Discovery
- T1102.002 Bidirectional Communication
- T1567.002 Exfiltration to Cloud Storage
- T1608.001 Upload Malware
- T1027 Obfuscated Files or Information
- T1574.002 DLL Side-Loading
- T1105 Ingress Tool Transfer
- T1083 File and Directory Discovery

## Sources

- [Cisco Talos: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor](https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/)
- [The Hacker News: Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign](https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html)
- [eSecurity Planet: China-Linked Hackers Use Antino Backdoor in Asia](https://www.esecurityplanet.com/cybersecurity-threats/news-uat-11587-antino-backdoor-microsoft-365-cloudflare/)
- [SOC Prime: UAT-11587 Deploys Antino Backdoor in Asia](https://socprime.com/active-threats/uat-11587-targets-asian-government-and-policy-organizations-with-antino-backdoor/)
- [Cyberpress: China-Nexus UAT-11587 Compromises 350 Endpoints Across Eight Countries](https://cyberpress.org/china-breaches-350-asian-endpoints/)
- [SecurityOnline: UAT-11587 Targets Asian Governments With Antino Backdoor](https://securityonline.info/uat-11587-antino-backdoor/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2848
