Antino Malware Campaign Uses Outlook And OneDrive For Espionage Operations Across Asia

Published:

Government and policy organizations across Asia have been targeted in a cyber espionage campaign involving a previously undocumented backdoor named Antino. Security researchers at Cisco Talos are tracking the activity under the name UAT-11587 and have linked the campaign to a China nexus threat actor with high confidence based on multiple technical and contextual indicators. The campaign has affected organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, with researchers identifying attacks against 16 entities across eight Asian countries since activity was first observed in September 2025.

Cisco Talos researchers said Antino is a Rust compiled Windows backdoor designed to conduct system reconnaissance, execute commands, transfer files, load shellcode in memory, and establish persistence on compromised systems. Unlike many malware families that rely on dedicated command and control servers, Antino uses Microsoft 365 services as its communication channel. The malware interacts with Microsoft Graph APIs to use Outlook and OneDrive as part of its command and control infrastructure, allowing attackers to exchange commands, maintain communication, and transfer files while blending activity into commonly used cloud services. Researchers said UAT-11587 shows some operational similarities with Jewelbug and other China aligned activity clusters, including CL-STA-0049, Earth Alux, Ink Dragon, and REF7707. However, Cisco Talos noted that its investigation did not identify a direct connection between this campaign and Jewelbug’s reported financially motivated operations, leading researchers to track UAT-11587 as a separate activity set. The assessment that the activity has China nexus characteristics is based on several factors, including Simplified Chinese metadata and zh-CN language indicators found in lure documents, the use of the UTC+08:00 time zone in phishing message headers, and targeting patterns involving government, diplomatic, maritime, security, and policy related organizations.

Additional technical evidence identified by researchers includes nearly a dozen Antino build outputs containing Cargo registry paths referencing rsproxy.cn, a domestic mirror and proxy service for the Rust crates ecosystem used in mainland China. Researchers also identified a JavaScript downloader connected to UAT-11587 that referenced a CloudFront domain previously associated by Arctic Wolf with a campaign attributed to a China affiliated threat actor targeting European diplomatic and government entities. While the majority of observed activity focused on Asian organizations, Cisco Talos also found evidence suggesting the threat actor targeted organizations in Syria around May 2026, indicating that the campaign may extend beyond the region. The attack chain begins with carefully prepared spear phishing emails designed to increase the likelihood of interaction from targeted recipients. Researchers said the attackers appeared to conduct reconnaissance of their targets and customized lure content around foreign affairs, international security, and government policy themes. To improve credibility, the campaign used spoofed sender identities and attempted to bypass email security controls, including SPF and DMARC checks. In some cases, attackers recreated Gmail’s attachment preview interface inside email HTML content using Base64 encoded images, creating a fake attachment card that appeared similar to a legitimate Gmail preview. When users interacted with the embedded link, they were redirected to attacker controlled Cloudflare Pages URLs that initiated the malware delivery process.

According to Cisco Talos, the infection chain follows a five stage process beginning with an HTA or WSF stager and ending with the deployment of the Antino backdoor. The phishing link delivers an HTA or WSF file that retrieves a JavaScript downloader and decryptor. This stage launches a .NET deserialization process that loads TestAssembly.dll, which downloads the legitimate looking lure document, a decoy Calculator executable, and the Antino malware implant. The backdoor, identified as slc.dll, is then executed through DLL sideloading using a legitimate Microsoft signed binary called GatherOsState.exe. Once active on a compromised system, Antino can collect host information, list running processes, enumerate directories, execute PowerShell scripts, run operator supplied programs, and execute commands through cmd.exe. For command and control operations, the malware checks an attacker controlled Outlook mailbox folder every 10 seconds for messages containing a specific subject format beginning with “command_req_[session_id].” It uses Outlook for command exchanges and OneDrive for heartbeat signals and file transfers. Cisco Talos researchers noted that Antino also abuses the Windows Scripted Diagnostics framework to execute attacker controlled PowerShell through legitimate Windows components, which may make attribution more difficult but still leaves detectable activity through PowerShell execution, file creation, and Registry changes.

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img