securityonline.info 2 Oct 2026, 08:01 UTC

China-Linked Hackers Hide Antino Espionage in Microsoft 365 Traffic

China-Linked Hackers Hide Antino Espionage in Microsoft 365 Traffic
CyberSIXT Evidence Panel
Threat Actor
UAT-11587

CISCO Talos has identified a China-nexus espionage operation, attributed to UAT-11587, that targeted government, military and policy bodies across Asia. In September 2025, the group deployed the Antino backdoor across roughly 350 endpoints in eight countries, leveraging Microsoft 365 cloud services for command-and-control and data exfiltration.

The campaign’s most notable feature was its use of DLL sideloading and dead-drop channels via Microsoft Graph API to blend malicious activity with normal enterprise communications, with tokens authenticated through legitimate cloud services.

The attack chain began with spear-phishing messages that spoofed trusted senders through domain misalignment. Recipients faced cloned Gmail attachment cards that nerved users toward Cloudflare Pages-hosted malicious files. A multi-stage infection followed: a Microsoft HTML Application host pulled a secondary script from cloud storage, which performed in-memory deserialization to load a launcher that unpacked decoy documents and binaries.

The core implant then relied on sideloading using GatherOsState[.]exe to load a malicious library, slc[.]dll, which started the Antino backdoor. Post-infection activity included memory concealment, sleep function hooks, and read-only memory protection during idle periods. When active, the backdoor decrypted memory blocks via an exception handler and used the Windows Scripted Diagnostics framework to execute PowerShell, enabling registry run-key modifications and ongoing C2.

Cisco Talos links UAT-11587 to a China-nexus cluster, with overlaps to Jewelbug per Symantec and infrastructure ties to other Chinese intrusion sets. Impact was regional but demonstrated systemic use of Office 365-based exfiltration channels and Cloudflare delivery infrastructure. Defenders are urged to enforce strict email authentication, reject unaligned emails, block unsigned executables in temp directories, and scrutinise Entra ID app registrations for unusual Graph API activity.

View full article

Article by CyberSIXT