Executive Summary
A newly identified China-nexus cyber-espionage campaign is leveraging a sophisticated Rust-based backdoor, Antino, to target government, defense, and policy organizations across Asia and the Middle East. What sets this campaign apart is its abuse of Microsoft Outlook and OneDrive—core components of the Microsoft 365 suite—as covert command-and-control (C2) channels. By embedding malicious C2 traffic within legitimate enterprise cloud activity, the threat actor achieves a high degree of stealth, complicating detection and response efforts. The campaign, attributed to the cluster UAT-11587, demonstrates advanced tradecraft, including multi-stage infection chains, DLL sideloading, and the use of trusted cloud APIs for persistent access and data exfiltration. This report provides a technical deep dive into the Antino backdoor, its tactics, techniques, and procedures (TTPs), observed exploitation in the wild, and actionable mitigation strategies for defenders.
Threat Actor Profile
The campaign is attributed to a China-nexus threat cluster tracked as UAT-11587. This actor is characterized by its focus on intelligence collection from government, defense, and policy organizations in Asia and the Middle East. The group demonstrates operational overlaps with other known Chinese APTs, including Jewelbug, CL-STA-0049, Earth Alux, Ink Dragon, REF7707, and UNC6384. The actor’s infrastructure, malware development practices, and targeting patterns are consistent with state-sponsored cyber-espionage objectives. Notably, UAT-11587 employs advanced social engineering, custom malware development in Rust, and the abuse of legitimate cloud services to evade traditional security controls.
Technical Analysis of Malware/TTPs
The infection chain begins with highly targeted spear-phishing emails, often themed around regional politics, legislative affairs, or diplomatic events. These emails spoof trusted senders and employ convincing HTML lures, such as mimicking Gmail’s attachment preview interface. The initial payload is typically a malicious HTA or WSF file hosted on Cloudflare Pages. When executed, this stager uses mshta.exe or Windows Script Host to fetch a JavaScript loader from attacker-controlled infrastructure.
The loader decrypts and executes three resources: a JavaScript orchestrator and two .NET-based components. The .NET stage abuses unsafe BinaryFormatter deserialization to load a malicious assembly (TestAssembly.dll) directly into memory, bypassing disk-based detection. This stage downloads a decoy document, a benign Calculator executable, and the Antino backdoor bundle.
Persistence is achieved via a HKCU Run registry key and by staging files under %LOCALAPPDATA%\Windows GatherOSStateKit\. The campaign employs DLL sideloading by executing a legitimate GatherOsState.exe (a Microsoft-signed binary) alongside a malicious slc.dll (the actual Antino payload).
Antino is a modular backdoor written in Rust, compiled for both 32-bit and 64-bit architectures, and delivered as either a DLL or EXE. Its C2 mechanism is highly innovative: it uses the Microsoft Graph API to interact with attacker-controlled Outlook mailboxes and OneDrive storage. The implant polls Outlook folders every 10 seconds for commands (using a subject prefix like command_req_[session_id]) and synchronizes with OneDrive every minute for heartbeat and file transfer operations. All C2 traffic is encrypted and blends seamlessly with legitimate Microsoft 365 activity.
The backdoor supports a wide range of post-exploitation capabilities, including host reconnaissance, arbitrary command execution (via cmd.exe and PowerShell), directory and file enumeration, file upload/download, in-memory shellcode execution, and self-termination. To evade detection, Antino employs sleep-masking techniques and proxies PowerShell execution through Windows Scripted Diagnostics (sdiagnhost.exe).
Exploitation in the Wild
The campaign has been active since at least September 2025, with a significant uptick in activity observed between March and June 2026. Over 350 endpoints across at least 16 organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria have been compromised. Victims include government agencies, defense and national security organizations, diplomatic services, law enforcement, legislative institutions, IT service providers, universities, think tanks, and civil-society groups. Attack waves have been observed to coincide with major regional political events, suggesting a strong intelligence-gathering motive.
Victimology and Targeting
The targeting profile is highly selective and consistent with state-sponsored espionage. The primary victims are government and defense entities, policy research organizations, and diplomatic missions. Secondary targets include legislative bodies, law enforcement, and academic institutions involved in policy analysis or international relations. The campaign’s geographic focus spans Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria, reflecting strategic interests in regional security and political developments.
Mitigation and Countermeasures
Defenders should implement a multi-layered approach to detect and mitigate this threat. Continuous monitoring for unusual mshta.exe or Windows Script Host activity, especially processes fetching remote content from Cloudflare or Amazon CloudFront, is critical. Security teams should scrutinize the execution of GatherOsState.exe from user-writable directories, particularly when accompanied by a suspicious slc.dll. Endpoint detection and response (EDR) solutions should be configured to alert on anomalous sdiagnhost.exe activity and PowerShell execution patterns.
Network defenders must correlate OneDrive and Outlook activity with endpoint anomalies, as all C2 traffic leverages the Microsoft Graph API and blends with legitimate enterprise cloud usage. Hunting for persistence mechanisms, such as registry keys at HKCU\Software\Microsoft\Windows\CurrentVersion\Run and files under %LOCALAPPDATA%\Windows GatherOSStateKit\, is recommended. Organizations should also review email security controls to detect and block spear-phishing attempts, including the use of spoofed sender identities and malicious HTML attachments.
Given the abuse of legitimate cloud APIs, traditional network filtering is insufficient. Behavioral analytics, anomaly detection, and robust endpoint monitoring are essential. Regular threat hunting for known indicators of compromise (IOCs), such as connections to rsproxy[.]cn, d32tpl7xt7175h.cloudfront[.]net, and suspicious Microsoft Graph API usage, will enhance detection capabilities. Refer to the latest threat intelligence feeds and the original Cisco Talos research for updated IOCs and detection signatures.
References
- The Hacker News: Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
- eSecurityPlanet: China-Linked Hackers Use Antino Backdoor in Asia
- Cisco Talos (original research, referenced in above articles)
- MITRE ATT&CK
About Rescana
Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to continuously assess, monitor, and mitigate cyber risks across their extended supply chain. Our platform leverages advanced analytics, threat intelligence, and automation to deliver actionable insights and help organizations stay ahead of emerging threats. For more information about how Rescana can help your organization strengthen its cyber resilience, or if you have any questions about this report, please contact us at info@rescana.com.



