Close Menu
NCIJ Network NCIJ Network
    What's Hot

    In Rare Move, Alleged Iranian State Hacker Extradited to US

    October 2, 2026

    IMF Praises El Salvador But Tries To Scale Back Bitcoin Use

    October 2, 2026

    Federal Judge Slams the Brakes on Big Bend Border Wall Construction

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • In Rare Move, Alleged Iranian State Hacker Extradited to US
    • IMF Praises El Salvador But Tries To Scale Back Bitcoin Use
    • Federal Judge Slams the Brakes on Big Bend Border Wall Construction
    • How Sea Cucumbers Drive Crime From China to Mexico
    • Flydubai pilot recounts cockpit stabbing in call with Indian PM Modi | Aviation News
    • Bosses of three firms that supply trains to UK railways made £3.5m last year | Rail industry
    • iPhone 18 Pro Max stuck in SOS mode? Try AT&T’s urgent fix ASAP
    • Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 2, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor.

    The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster under the moniker UAT-11587.

    The threat actor was first detected in September 2025 in connection with a spear-phishing campaign directed against Taiwan’s academic, think tank, and civil society policy community. Since then, attacks linked to the intrusion set have expanded to target 16 entities across eight Asian countries.

    “Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence,” security researcher Ashley Shen said. “Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.”

    UAT-11587 is assessed to share some level of overlap with Jewelbug, which, in turn, exhibits tactical similarities with China-aligned clusters known as CL-STA-0049, Earth Alux, Ink Dragon, and REF7707. A report published by Broadcom-owned Symantec and Carbon Black in August 2026 characterized Jewelbug as a China-based hackers-for-hire group that carries out espionage operations and a for-profit cryptocurrency fraud business.

    However, Cisco Talos said its own investigation has failed to unearth a connection between the espionage campaign and Jewelbug’s financially motivated activity, prompting it to designate UAT-11587 as a separate activity set.

    Cybersecurity

    The challenges in establishing definitive links notwithstanding, the adversary has been classified as China-nexus with high confidence, citing the presence of zh-CN language and Simplified Chinese metadata in the lure documents and the UTC+08:00 time zone in the spear-phishing message header.

    “The campaign’s lure theme and targeting provide additional contextual support,” Talos said. “Its lures and observed targets include Taiwanese political, legislative, civil defense, and policy research subjects, together with regional government, maritime, diplomatic, and security themes. This collection focus is consistent with China-nexus actor interests.”

    Two other indicators that point to a China-nexus are below –

    • Nearly a dozen distinct Antino build outputs feature Cargo registry paths referencing rsproxy[.]cn, a high-speed domestic mirror and proxy service for crates.io catering to mainland China
    • A JavaScript downloader associated with UAT-11587 that references “d32tpl7xt7175h.cloudfront[.]net,” a CloudFront domain previously flagged by Arctic Wolf in connection with a campaign conducted by a China-affiliated threat actor known as UNC6384 targeting European diplomatic and government entities last year using an unpatched Windows shortcut vulnerability.

    Evidence indicates that UAT-11587 has also trained its sights on organizations in Syria around May 2026, indicating a focus beyond Asia. Attacks mounted by the threat actor have been found to spike between March and early June 2026, with a “concentrated wave” taking place on June 8 and 9, 2026, targeting dozens of systems associated with government IT infrastructure.

    While the choice of spear-phishing as an initial access vector is unsurprising, the choice of the lures employed suggests the threat actor conducted extensive reconnaissance of the target organizations in order to tailor the content and maximize the chance of success.

    In an attempt to lend credibility to the emails, UAT-11587 is said to have spoofed sender identities trusted by the intended recipients to bypass SPF and DMARC security checks and ensure that the messages land on the victims’ inboxes.

    “Another social engineering technique used for initial access in this campaign was the closely replicated reconstruction of Gmail’s native attachment preview widget inside the email HTML body,” Shen explained. “The actor replicated the styling of Gmail’s attachment card using four inline PNG images embedded as Base64-encoded MIME parts.”

    “The entire attachment card was wrapped in an anchor tag pointing to an attacker-controlled [Cloudflare Pages] URL. When a Gmail user opens the email in a browser, Gmail’s renderer faithfully displays the attacker-controlled HTML, producing a fake attachment widget that is visually indistinguishable from a legitimate Gmail attachment preview.”

    An analysis of the lures demonstrates a propensity to target audiences interested in foreign affairs, international security, and government policy, Talos added. The attack chain itself is a five-stage process that begins with a HTA or WSF stager and culminates in the deployment of Antino.

    Cybersecurity

    The Cloudflare URL in the phishing email leads to the download of an HTA or WSF file that’s then executed to retrieve a JavaScript downloader and decryptor. The next stage triggers a .NET deserialization chain to load “TestAssembly.dll,” a .NET downloader and launcher that’s responsible for three actions –

    • Download and open the lure document to the victim.
    • Download a decoy Calculator executable.
    • Download and launch the Antino backdoor.

    The implant (“slc.dll”) is launched by means of DLL sideloading using a legitimate Microsoft-signed binary (“GatherOsState.exe”). Once launched, the Rust-compiled malware communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, instead of depending on a conspicuous dedicated command-and-control (C2) server.

    Antino is no different from other backdoors of its kind in that it supports host reconnaissance, command execution, and persistence. It can also list running processes, enumerate directories, run PowerShell scripts, shellcode, operator-supplied programs, and commands using “cmd.exe”

    For C2, it uses Outlook for command exchange and OneDrive for heartbeat and file transfer. Specifically, it fetches commands from the threat actor’s Outlook mailbox folder every 10 seconds by looking for messages with the subject prefix “command_req_[session_id].”

    “The Antino backdoor abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components,” Talos said. “This can complicate behavioral attribution to the original implant, although it does not eliminate observable PowerShell, file-creation, or Registry telemetry.”

    Antino Backdoor campaign ChinaNexus Espionage OneDrive outlook
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    In Rare Move, Alleged Iranian State Hacker Extradited to US

    Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

    Crypto Scammers Hijack Microsoft’s Official X Account

    Is It Fair to Blame ‘Rogue’ AI for Security Failures?

    GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

    ‘Maxi merde’: French presidential campaign rattled by a week of chaos – POLITICO

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    In Rare Move, Alleged Iranian State Hacker Extradited to US

    October 2, 2026

    IMF Praises El Salvador But Tries To Scale Back Bitcoin Use

    October 2, 2026

    Federal Judge Slams the Brakes on Big Bend Border Wall Construction

    October 2, 2026

    How Sea Cucumbers Drive Crime From China to Mexico

    October 2, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    In Rare Move, Alleged Iranian State Hacker Extradited to US

    October 2, 2026

    IMF Praises El Salvador But Tries To Scale Back Bitcoin Use

    October 2, 2026

    Federal Judge Slams the Brakes on Big Bend Border Wall Construction

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.