Antino Backdoor Hides C2 in Outlook, OneDrive
A China-nexus actor is using Microsoft 365 mailboxes and cloud storage as dead drops to command a Rust-compiled Windows backdoor, Talos reports.
Government and policy organizations across Asia are being hit by a backdoor that never needs to phone home to an obvious server. Instead, according to Cisco Talos, the implant quietly reads instructions from an Outlook mailbox folder and uses OneDrive to check in and move files.
The campaign, tracked by Talos under the cluster name UAT-11587, deploys a previously undocumented Rust-compiled backdoor codenamed Antino. Talos says the intrusion set has hit government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar.
Talos first spotted the actor in September 2025, tied to a spear-phishing push against Taiwan's academic, think tank, and civil society policy community. From there, the activity expanded: the company says attacks linked to the set have since reached 16 entities across eight Asian countries.
A Rust Implant Built for Microsoft 365
Antino is a Windows backdoor written in Rust, and its command-and-control channel runs entirely through Microsoft 365. The malware uses Microsoft Graph to interact with Outlook and OneDrive rather than a dedicated C2 server that a network blocklist might catch.
For command exchange, it polls the operator's Outlook mailbox folder. Talos says it fetches commands every 10 seconds by looking for messages whose subject line carries the prefix "command_req_[session_id]". OneDrive handles heartbeat traffic and file transfer.
The backdoor's feature set is broad: host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading, and persistence. It can also list running processes, enumerate directories, and run operator-supplied programs or commands through "cmd.exe".
"Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence," security researcher Ashley Shen said. "Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive."
— Ashley Shen, security researcher at Cisco Talos
From Cloudflare Link to Sideloaded DLL
The access chain is a five-stage process that begins with an HTA or WSF stager and ends with Antino running on the host.
The phishing email carries a link to an attacker-controlled Cloudflare Pages URL. Clicking it downloads an HTA or WSF file, which executes and retrieves a JavaScript downloader and decryptor. That stage then triggers a .NET deserialization chain to load TestAssembly.dll, a .NET downloader and launcher.
TestAssembly.dll performs three actions, per Talos:
- Download and open the lure document for the victim
- Download a decoy Calculator executable
- Download and launch the Antino backdoor
The implant itself, named slc.dll, is launched through DLL sideloading using a legitimate Microsoft-signed binary, GatherOsState.exe.
Once running, Antino leans on the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components. Talos notes this can complicate behavioral attribution to the original implant, though it does not eliminate observable PowerShell, file-creation, or Registry telemetry.
Fake Gmail Card, Spoofed Senders
Talos says the lure themes point to extensive reconnaissance of the target organizations, with content tailored to maximize the chance of a click. The lures target audiences interested in foreign affairs, international security, and government policy.
To get past email defenses, UAT-11587 spoofed sender identities that recipients would trust, aiming to bypass SPF and DMARC security checks and land in inboxes.
A second social engineering trick was a near-exact reconstruction of Gmail's native attachment preview widget inside the email HTML body.
"Another social engineering technique used for initial access in this campaign was the closely replicated reconstruction of Gmail's native attachment preview widget inside the email HTML body," Shen explained. "The actor replicated the styling of Gmail's attachment card using four inline PNG images embedded as Base64-encoded MIME parts."
"The entire attachment card was wrapped in an anchor tag pointing to an attacker-controlled [Cloudflare Pages] URL. When a Gmail user opens the email in a browser, Gmail's renderer faithfully displays the attacker-controlled HTML, producing a fake attachment widget that is visually indistinguishable from a legitimate Gmail attachment preview."
— Ashley Shen, security researcher at Cisco Talos
Timeline and Geographic Spread
Talos tracks the actor's activity from its first detection in September 2025 through a broader 2026 push. Attacks attributed to UAT-11587 spiked between March and early June 2026, with a concentrated wave on June 8 and 9, 2026 that targeted dozens of systems tied to government IT infrastructure.
The targeting has not been limited to Asia. Talos says evidence indicates UAT-11587 also trained its sights on organizations in Syria around May 2026.
The lure themes include Taiwanese political, legislative, civil defense, and policy research subjects, alongside regional government, maritime, diplomatic, and security topics.
Why Talos Calls It China-Nexus
Talos classified the adversary as China-nexus with high confidence. The company cites zh-CN language and Simplified Chinese metadata in the lure documents, and the UTC+08:00 time zone in the spear-phishing message header.
"The campaign's lure theme and targeting provide additional contextual support," Talos said. "Its lures and observed targets include Taiwanese political, legislative, civil defense, and policy research subjects, together with regional government, maritime, diplomatic, and security themes. This collection focus is consistent with China-nexus actor interests."
Talos points to two further indicators:
- Nearly a dozen distinct Antino build outputs feature Cargo registry paths referencing rsproxy[.]cn, described as a high-speed domestic mirror and proxy service for crates.io catering to mainland China.
- A JavaScript downloader associated with UAT-11587 references "d32tpl7xt7175h.cloudfront[.]net," a CloudFront domain previously flagged by Arctic Wolf in connection with a campaign by a China-affiliated threat actor known as UNC6384 that targeted European diplomatic and government entities last year using an unpatched Windows shortcut vulnerability.
Overlap With Jewelbug, But a Separate Set
Talos assesses that UAT-11587 shares some level of overlap with Jewelbug, which in turn shows tactical similarities with China-aligned clusters known as CL-STA-0049, Earth Alux, Ink Dragon, and REF7707.
A report published by Broadcom-owned Symantec and Carbon Black in August 2026 characterized Jewelbug as a China-based hackers-for-hire group that carries out espionage operations and a for-profit cryptocurrency fraud business.
Talos said its own investigation did not find a connection between the espionage campaign and Jewelbug's financially motivated activity, which is why it designated UAT-11587 as a separate activity set.
How the Implant Evades Behavioral Ties
Using Outlook and OneDrive as dead drops is central to the implant's design. Rather than depending on a conspicuous dedicated C2 server, Antino blends its traffic into services that most enterprises already allow and monitor less aggressively.
The Scripted Diagnostics technique adds another layer. By routing PowerShell execution through legitimate Windows components, the operator makes it harder to tie activity back to the original implant. Talos is explicit that this does not eliminate observable telemetry — PowerShell, file-creation, and Registry events can still surface — but it complicates attribution.
The build artifacts also carry markers. Nearly a dozen Antino builds show Cargo registry paths pointing at rsproxy[.]cn, a detail Talos includes among its China-nexus indicators.
What the Campaign Means for Defenders
Talos' account is currently the primary detailed report on UAT-11587, and its links to Jewelbug and other clusters remain assessments rather than settled facts. For organizations in government, policy, and adjacent sectors, the reported tradecraft suggests the trust placed in mainstream productivity suites can be turned into cover. A backdoor that checks an Outlook folder for instructions does not need to beacon to a domain that a blocklist would catch, which could raise the stakes for anyone relying on network-level indicators alone.
The targeting pattern also points to reconnaissance as a force multiplier. Lures built around foreign affairs, maritime, diplomatic, and security themes, plus a cloned Gmail widget, increase the chance that a busy policy staffer clicks before thinking. That suggests awareness efforts may need to focus less on generic phishing warnings and more on the specific rendering tricks in play.
For security teams, the practical upshot is that endpoint and identity telemetry may carry more weight than domain blocklists in cases like this. Logging around Microsoft Graph activity, unusual DLL sideloading paths, and PowerShell execution through Windows diagnostics components could be the evidence that surfaces an intrusion using this technique.
Sources
- The Hacker News Original source
- UNC6384 Also reporting
- SPF and DMARC security checks Also reporting
Continue Reading
Nvidia chip smuggling case carries 50-year max
A California business owner faces charges of allegedly exporting around $300 million in advanced Nvidia hardware to China without required licenses.
Microsoft X Account Hijacked for Crypto Scam
Microsoft's X account with 13 million followers was hijacked to push a Clippy-themed crypto token, and the company has yet to explain how.
Teen ran KillSec ransomware, cops say
A 16-year-old led a ransomware crew that claimed about 1,000 attacks, according to European police.