thehackernews.com 2 Oct 2026, 17:33 UTC

China-Linked Antino Backdoor Targets Asian Government Bodies via Microsoft 365

CyberSIXT Evidence Panel
Threat Actor
UAT-11587

CISCO Talos has disclosed a China-nexus espionage operation targeting government and policy bodies across eight Asian nations, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. The group’s backdoor, codenamed Antino and tracked as UAT-11587, first surfaced in September 2025 during a spear-phishing campaign affecting Taiwan’s academic, think tank, and civil society policy sector.

Since then, the activity expanded to at least 16 entities across eight countries, with a notable emphasis on regional political and security themes. Antino is a Rust-compiled Windows backdoor capable of host reconnaissance, shell and PowerShell execution, file transfers, in-memory shellcode loading and persistence, and it communicates with its operators through a native C2 channel that operates exclusively via Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.

Talos cautions that UAT-11587 partly overlaps with Jewelbug and related China-aligned clusters, though Cisco’s investigation has not confirmed a direct link to Jewelbug’s financially motivated activity. The threat is characterised by targeted, well-researched lure documents in Simplified Chinese, use of spoofed sender identities to bypass SPF/DMARC, and a Gmail attachment-widget mimicry to deceive recipients.

The intrusion chain is a five-stage process beginning with an HTA or WSF stager, leading to a JavaScript downloader, a .NET deserialization stage, and finally the Antino implant (slc[.]dll) loaded via DLL sideloading using GatherOsState[.]exe. Once active, Antino uses Outlook for command exchanges and OneDrive for heartbeats and data exfiltration, with commands polled from a folder named command_req_[session_id] every 10 seconds.

Evidence also notes several Cloudflare and CloudFront indicators and a focus that extended to Syria in mid-2026, with intensified activity in March–June 2026 and a concentrated wave on 8–9 June 2026. No CVEs or specific software versions are cited in the available material. Practical responses include continued monitoring of Microsoft 365-based C2 channels, strict email authentication enforcement, and user awareness around tailored spear-phishing lures. SOURCE_UNAVAILABLE

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline