China
Cisco Talos researchers have uncovered a China-nexus espionage campaign targeting government and policy organizations across Asia with a novel Rust-based backdoor that abuses Microsoft 365 services for covert communications.
A China-aligned threat actor tracked as UAT-11587 has compromised at least 16 government and policy organizations across eight Asian countries since September 2025, deploying a previously undocumented backdoor that communicates exclusively through Microsoft Outlook and OneDrive.
The malware, dubbed Antino, is a Rust-compiled Windows implant that uses Microsoft Graph APIs to interact with Outlook for command retrieval and OneDrive for heartbeat signals and file transfers — eliminating the need for a traditional command-and-control server.
"Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence," Cisco Talos researcher Ashley Shen said. "Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive."
Campaign Scope and Targeting
The campaign has hit targets in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and more recently Syria. Talos observed a sharp spike in activity between March and early June 2026, culminating in a concentrated wave on June 8–9 that struck dozens of systems tied to government IT infrastructure.
Lure documents focus on Taiwanese political, legislative, civil defense, and policy research topics, along with regional maritime, diplomatic, and security themes — a targeting profile consistent with Chinese intelligence priorities.
Technical Architecture
The infection chain unfolds in five stages:
Initial access via spear-phishing emails that spoof trusted senders to bypass SPF and DMARC checks. The emails embed a fake Gmail attachment preview widget — built from four Base64-encoded PNG images wrapped in an anchor tag pointing to a Cloudflare Pages URL.
Stager execution — clicking the link downloads an HTA or WSF file that retrieves a JavaScript downloader and decryptor.
.NET deserialization chain loads "TestAssembly.dll," a .NET downloader that opens a lure document, drops a decoy Calculator executable, and launches the Antino backdoor.
DLL sideloading — the implant (slc.dll) loads via a legitimate Microsoft-signed binary, GatherOsState.exe.
C2 operations — Antino polls the attacker's Outlook mailbox every 10 seconds for messages with the subject prefix "command_req_[session_id]" and uses OneDrive for data exfiltration and heartbeat.
The backdoor also abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate system components, complicating behavioral attribution.
Attribution Indicators
Talos assesses UAT-11587 as China-nexus with high confidence based on multiple artifacts:
Simplified Chinese metadata and zh-CN language in lure documents
UTC+08:00 time zone in email headers
Nearly a dozen Antino builds reference rsproxy.cn, a domestic crates.io mirror for mainland China
A JavaScript downloader references a CloudFront domain (d32tpl7xt7175h.cloudfront.net) previously linked by Arctic Wolf to UNC6384, a China-affiliated actor that targeted European diplomatic entities in 2025
Talos notes tactical overlap with a cluster known as Jewelbug — characterized by Symantec and Carbon Black in August 2026 as a China-based hackers-for-hire group conducting both espionage and cryptocurrency fraud — but found no evidence linking UAT-11587 to Jewelbug's financially motivated operations.
Organizations should monitor for anomalous Microsoft Graph API activity, particularly unusual Outlook mailbox access patterns and OneDrive file operations from endpoints. The use of legitimate Microsoft 365 infrastructure for C2 makes network-based detection difficult; endpoint telemetry covering PowerShell execution, DLL sideloading via GatherOsState.exe, and Windows Scripted Diagnostics abuse offers better visibility.
Talos has published indicators of compromise including file hashes, Cloudflare Pages URLs, and the CloudFront domain in its advisory.
Source : thehackernews.com
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
