Antino backdoor infection chain | Image: Cisco Talos
At a Glance
| Attribute | Details |
|---|---|
| Actor or Group | UAT-11587 (suspected China-nexus group; overlaps with Jewelbug) |
| Activity Type | Cyberespionage, spear-phishing, DLL sideloading, dead-drop C2 |
| Targets or Victims | Government, military, think tanks, and policy bodies across Asia |
| Scale | Approximately 350 compromised endpoints across eight countries |
| Jurisdiction / Status | Suspected Chinese state-sponsored threat group; uncharged |
| Source | Cisco Talos (with reference to Symantec research) |
Executive Summary
Cisco Talos uncovered an espionage operation in September 2025 that deployed the Antino backdoor against Asian government networks. The campaign compromised approximately 350 endpoints across eight countries by abusing Microsoft 365 cloud services. Furthermore, researchers linked these intrusions to a suspected Chinese state-sponsored threat group.
What Happened
The threat actors initiated their intrusions through targeted spear-phishing messages. Specifically, the attackers spoofed trusted email senders by abusing domain misalignment. The messages passed sender authentication because the envelope domain matched the sending server. However, receiving servers accepted the emails because the displayed domain used an unenforced policy.
In addition, the phishing emails contained cloned Gmail attachment cards. The attackers built these fake cards using inline images to trick users. When clicked, the link directed victims to malicious files hosted on Cloudflare Pages.
The attack launched a multi-stage infection sequence. First, the Microsoft HTML Application host downloaded a secondary script from cloud storage. Next, the script executed an in-memory deserialization routine using standard Windows components. This routine loaded a launcher library that unpacked decoy documents and binary files.
To execute the core implant, the launcher relied on DLL sideloading. It abused a legitimate, signed Microsoft utility named GatherOsState.exe. This executable loaded a malicious library named slc.dll, which started the Antino backdoor. Talos noted, “The actor relied heavily on Cloudflare infrastructure for delivery, execution tracking, and payload staging.”
Once active, the backdoor masked its memory presence. The implant hooked system sleep functions and changed memory protections to read-only during idle periods. When execution resumed, an exception handler decrypted the memory block. Furthermore, the malware abused the Windows Scripted Diagnostics framework to execute PowerShell commands. This mechanism allowed the backdoor to modify registry run keys without direct execution flags.
Who Is Behind It
Cisco Talos assesses with high confidence that UAT-11587 is a China-nexus espionage group. Technical evidence from preparation environments supports this attribution. For example, decoy metadata contained Simplified Chinese author tags and a UTC+8 creation timestamp. Moreover, internal compiler paths showed dependencies downloaded from a Chinese Rust package mirror.
Independent research from Symantec revealed operational overlaps with an activity cluster called Jewelbug. Symantec observed that Jewelbug conducted both espionage and cryptocurrency fraud. However, Symantec assessed that an external service provider supplied infrastructure to the espionage group. Talos also noted infrastructure overlaps with Chinese intrusion sets documented by Arctic Wolf. Consequently, Talos tracks UAT-11587 as an independent intelligence operation.
Impact and Scale
The campaign targeted public-sector and national security entities across Asia. Talos identified 16 targeted institutional environments across eight countries. The affected regions included Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria.
Overall, the investigation confirmed approximately 350 compromised endpoints. The largest wave occurred in June 2026, when attackers infected 57 systems in India’s shared government infrastructure. The threat actors selected lures tailored to each region, focusing on cross-strait relations and maritime security.
The backdoor relied on Microsoft 365 for command-and-control operations. It authenticated through application programming interfaces using cloud tokens. As Cisco Talos reported, “Antino communicates exclusively through Microsoft 365, using the Microsoft Graph API to interact with Outlook and OneDrive as dead-drop C2 channels.”
The implant queried an Outlook mailbox every 10 seconds for new operator commands. Meanwhile, it uploaded host telemetry files to OneDrive folders every minute. This design allowed malicious traffic to blend into legitimate enterprise communications.
How to Stay Protected
Organizations must implement strict email authentication policies to stop sender spoofing. Administrators should configure domain policies to reject unaligned email traffic. In addition, security teams should block unsigned executables from running inside temporary directories.
Defenders should also inspect Microsoft Entra ID application registrations for unapproved permissions. Monitoring unexpected Graph API calls from endpoint utilities helps expose hidden channels. Auditing signed binaries that load external libraries will help organizations prevent unauthorized sideloading.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!