China-Linked Hackers Target Asian Governments With Antino Backdoor

Cisco Talos linked UAT-11587 to an 11-month espionage campaign using Antino, cloud infrastructure, and Microsoft 365 C2 across Asia.

Oct 2, 2026
5 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Cisco Talos has uncovered an 11-month cyberespionage campaign linked to UAT-11587, a China-nexus threat actor targeting government and policy organizations across Asia. The group deployed Antino, a previously undocumented Rust-compiled Windows backdoor that uses Microsoft 365 for command-and-control communications.

By July 2026, Talos had identified at least 10 confirmed and five probable affected institutional environments, plus one additional intended target. Its investigation found approximately 350 compromised endpoints across eight countries.

The Cisco Talos investigation, published Sept. 30, traces UAT-11587 activity from September 2025 through July 2026 and assesses with high confidence that the actor is China-nexus.

UAT-11587 targeted organizations across eight countries

Talos assesses with moderate-to-high confidence that UAT-11587 targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria.

Targets included defense and national security organizations, executive government agencies, diplomatic services, law enforcement, legislative institutions, government IT services, universities, think tanks, and civil-society groups.

Talos first identified the campaign in March while investigating spear-phishing aimed at Taiwan's academic, think tank, and civil-society policy community. Earlier activity dated to September 2025 and included Philippines-themed lures.

Activity accelerated between March and early June. The largest concentrated wave came on June 8 and 9, when Talos identified about 57 newly observed endpoints associated with India.

The phishing lures were tailored to regional political and institutional interests. Some emails recreated Gmail's attachment interface, while recovered decoys referenced Taiwanese government policy, Indo-Pacific affairs, maritime issues, diplomatic events, and other subjects likely to interest government and policy targets.

Advertisement

Cloudflare delivered malware while Microsoft 365 handled C2

UAT-11587 divided its infrastructure across widely used cloud platforms.

Cloudflare Pages hosted malicious HTA and WSF files and an execution-tracking endpoint. Cloudflare R2 stored encoded loader stages, decoy documents, and payload components, while Amazon CloudFront delivered additional scripts and decoy material.

Once Antino was installed, however, its native command-and-control channel operated exclusively through Microsoft 365.

The backdoor used Microsoft Graph to communicate with Outlook and OneDrive. OneDrive handled implant registration, heartbeat traffic, tool delivery, and exfiltrated files, while Outlook carried commands and responses between Antino and its controller.

Talos found that Antino could poll an attacker-controlled Outlook mailbox for new commands every 10 seconds and upload heartbeat data to OneDrive every minute. Connections terminated at Microsoft domains commonly allowed in enterprise environments, allowing the traffic to blend with other trusted Microsoft services at the network layer.

How the Antino infection chain works

Talos documented a recurring five-stage infection chain beginning with targeted phishing.

The first stage delivers an HTA file executed through mshta.exe, or a WSF variant run through Windows Script Host. The stager hides its window, contacts a Cloudflare Pages tracking endpoint, and retrieves the next JavaScript stage from Cloudflare R2 or Amazon CloudFront.

The second stage downloads three encrypted resources: a JavaScript orchestrator and two serialized .NET gadget resources. It applies custom Base64 decoding and RC4 decryption before launching the next stage in memory.

Stage three abuses unsafe .NET BinaryFormatter deserialization. The resulting gadget chain loads a .NET assembly called TestAssembly.dll directly inside the running mshta.exe process.

That downloader retrieves a lure-specific decoy document and a three-file payload bundle. It then launches GatherOsState.exe, a legitimate Microsoft-signed Windows Assessment and Deployment Kit binary.

Advertisement

The final stage uses DLL sideloading. With the malicious slc.dll placed beside GatherOsState.exe, the trusted Microsoft binary loads the DLL and starts Antino.

Antino supports persistence, shell access, and file theft

Talos observed Antino in both 32-bit and 64-bit builds and in standalone executable and DLL forms.

Its supported commands include host reconnaissance, cmd.exe and PowerShell execution, directory enumeration, program execution, file upload and download, in-memory shellcode execution, persistence, and termination of the implant.

The backdoor can establish persistence through an HKCU Run registry value and stage files under %LOCALAPPDATA%\Windows GatherOSStateKit\.

Some builds also support a sleep-masking technique designed to reduce the amount of recognizable malicious code exposed to memory scanners while a secondary payload is inactive.

Antino further abuses the Windows Scripted Diagnostics framework to proxy attacker-controlled PowerShell through legitimate Windows components. Talos observed this technique being used for both program execution and persistence-related registry changes.

What defenders should monitor

Talos published extensive hashes, malicious domains, URLs, ClamAV signatures, and Snort rules for the campaign.

Endpoint teams can also hunt for behaviors that connect the individual stages of the infection chain:

  • mshta.exe or Windows Script Host retrieving remote content from unexpected Cloudflare Pages, R2, or CloudFront locations.
  • GatherOsState.exe executing from unexpected or user-writable directories, particularly when an slc.dll file is present beside it.
  • Unusual sdiagnhost.exe activity followed by PowerShell execution or HKCU Run key changes.
  • Suspicious process trees communicating with graph.microsoft.com or login.microsoftonline.com, rather than treating every connection to those domains as benign.
  • OneDrive and Outlook activity that correlates with endpoint indicators of compromise or other suspicious execution.

Microsoft Graph itself is not malicious, and legitimate applications rely heavily on it. Recent Microsoft Graph activity seen in other attacks reinforces the need to correlate cloud traffic with endpoint, process, identity, and application context instead of blocking Microsoft services outright.

Advertisement

Talos assesses with high confidence that UAT-11587 is a China-nexus actor based on multiple technical and operational indicators rather than a single artifact.

Researchers found Simplified Chinese metadata, UTC+8 preparation timestamps, repeated references to the China-focused rsproxy.cn Rust package mirror in Antino build artifacts, and targeting focused heavily on political, diplomatic, national-security, and policy organizations across Asia.

Talos also identified infrastructure overlap with previously reported China-nexus activity, although it assessed that particular connection with low confidence and continues to track UAT-11587 as a separate activity cluster.

The report does not attribute UAT-11587 to a specific Chinese government agency. Talos separately assesses with moderate confidence that the actor's sustained targeting and collection capabilities support an intelligence-gathering objective.

Talos observed campaign activity through July 2026, but its report does not establish that the operation ended then. Organizations in affected sectors can use the published indicators and behavioral patterns to hunt retrospectively for Antino activity that may predate the disclosure.

Also read: Google recently found China-linked hackers running AI models inside compromised networks while using victims' own cloud infrastructure.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.