CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

UAT-11587

actor · actor:uat-11587 single-source

Cluster Cisco Talos assesses with high confidence as China-nexus and with moderate confidence as intelligence-gathering, active since September 2025 against defense, central administration, justice, e-government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria, with about 350 compromised endpoints; it spear-phishes with a five-stage HTA-based chain that sideloads the Antino backdoor, whose only command channel is Microsoft 365 through Microsoft Graph (Cisco Talos, 2026-09-30).

Coverage
1
first 2026-10-02 → last 2026-10-02
Latest activity
2026-10-02
Talos: Antino's traffic ends only at Microsoft's Graph and login endpoints, so network telemetry shows only…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector · regions: apac
Sources cited
1
1 hosts

Defender insights

What each entry about UAT-11587 tells a defender to do, newest first.

2026-10-02NOTABLETalos: Antino's traffic ends only at Microsoft's Graph and login endpoints, so network telemetry shows only Microsoft

Triage · detection

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

uses

overlaps with

Story timeline

  1. 2026-10-02UAT-11587: a China-nexus cluster spear-phishes Asian government and policy bodies with Antino, a Rust backdoor whose only command channel is Microsoft 365 through Microsoft Graph
    active-threatsTalos: Antino's traffic ends only at Microsoft's Graph and login endpoints, so network telemetry shows only Microsoft
ATT&CK techniques (15 across 8 tactics)

15 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Resource DevelopmentAcquire Infrastructure: Web Services
  • Initial AccessPhishing: Spearphishing Link
  • ExecutionCommand and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: JavaScript · User Execution: Malicious File · Hijack Execution Flow: DLL
  • PersistenceBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • Privilege EscalationBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • StealthObfuscated Files or Information · Deobfuscate/Decode Files or Information · System Binary Proxy Execution: Mshta · Hijack Execution Flow: DLL · Reflective Code Loading · Social Engineering: Email Spoofing
  • Command and ControlWeb Service: Bidirectional Communication · Ingress Tool Transfer
  • ExfiltrationExfiltration Over C2 Channel

Resource Development TA0042

T1583.006Acquire Infrastructure: Web Services×1

Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web-based service that can be abused during later stages of the adversary lifecycle, such as during Command and Control (Web Service), Exfiltration Over Web Service, or Phishing. Using common services, such as those offered by Google, GitHub, or Twitter, makes it easier for adversaries to hide in expected noise. By utilizing a web service, adversaries can make it difficult to physically tie back operations to them.

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

Initial Access TA0001

T1566.002Phishing: Spearphishing Link×1

Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

Execution TA0002

T1059.001Command and Scripting Interpreter: PowerShell×1

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

Persistence TA0003

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

Privilege Escalation TA0004

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

T1140Deobfuscate/Decode Files or Information×1

Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

T1218.005System Binary Proxy Execution: Mshta×1

Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

T1620Reflective Code Loading×1

Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

T1684.002Social Engineering: Email Spoofing×1

Adversaries may fake, or spoof, a sender’s identity by modifying the value of relevant email headers in order to establish contact with victims under false pretenses. In addition to actual email content, email headers (such as the FROM header, which contains the email address of the sender) may also be modified. Email clients display these headers when emails appear in a victim's inbox, which may cause modified emails to appear as if they were from the spoofed entity.

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

Command and Control TA0011

T1102.002Web Service: Bidirectional Communication×1

Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet.

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

Exfiltration TA0010

T1041Exfiltration Over C2 Channel×1

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Evidence: 2026-10-02/uat-11587-antino-microsoft-graph-c2-asian-governments · ATT&CK page ↗

Entries about UAT-11587 (1)

2026-10-02 · view entry permalink →

NOTABLENATOB2

UAT-11587: a China-nexus cluster spear-phishes Asian government and policy bodies with Antino, a Rust backdoor whose only command channel is Microsoft 365 through Microsoft Graph

Cisco Talos tracks UAT-11587, first seen in September 2025, with at least 10 confirmed and five probable affected institutional environments and about 350 compromised endpoints across eight countries (Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria, listed at moderate-to-high confidence); the targets include defense, central administration, justice and law enforcement, government IT and e-government services, legislatures and policy research bodies (Cisco Talos, 2026-09-30). Talos assesses China-nexus with high confidence and intelligence gathering with moderate confidence, and notes overlaps with the Antino activity Symantec attributes to Jewelbug without being able to verify a link to Jewelbug's financially motivated activity (Cisco Talos, 2026-09-30).

Delivery is spear-phishing in which the envelope sender is an attacker-controlled domain relayed through Migadu while the visible From header shows the impersonated organization, so SPF passes for the envelope domain, DMARC alignment fails, and a p=none policy on the impersonated domain lets the message reach the inbox; the mail body reproduces Gmail's attachment widget as images linking to a Cloudflare Pages address (Cisco Talos, 2026-09-30). The five-stage chain starts with an HTA stager run by mshta.exe, then a JScript downloader and decryptor that pulls encrypted resources from Cloudflare R2 or CloudFront, then .NET deserialization gadgets that load a downloader assembly inside mshta.exe, which writes a decoy and a three-file bundle and launches the Microsoft-signed Windows ADK binary GatherOsState.exe; that binary sideloads an unexpected DLL, which is Antino (Cisco Talos, 2026-09-30).

Antino is a Rust backdoor whose second-generation build authenticates to Microsoft Graph with the OAuth 2.0 client-credentials flow of an Entra application, polls an Outlook folder every 10 seconds for command emails, sends a OneDrive heartbeat every minute and uses OneDrive folders for tool staging and exfiltration, so outbound traffic ends only at graph.microsoft.com and login.microsoftonline.com (Cisco Talos, 2026-09-30). Its commands run cmd.exe and PowerShell, list, upload and download files, load shellcode in memory and add a registry Run value; execution and persistence abuse the Windows Scripted Diagnostics workflow, in which sdiagnhost.exe runs an attacker-written PowerShell script that writes the HKCU Run value (Cisco Talos, 2026-09-30).

Exposure: mail recipients whose organization's domain publishes DMARC p=none (the policy that let the reviewed message through), and endpoints where mshta.exe and Windows Script Host can run; Talos names no European victim.

Triage: Microsoft Graph traffic and signed Windows ADK binaries are both normal; the signal is the combination of GatherOsState.exe running from a staging directory outside the Windows ADK install, beside an unexpected DLL and that process then holding Graph connections.

Antino communicates exclusively through Microsoft 365, using the Microsoft Graph API to interact with Outlook and OneDrive as dead-drop C2 channels.

In the reviewed message, the displayed domain used a non-enforcing p=none policy, which requested monitoring rather than quarantine or rejection.

Talos could not independently verify a connection between the espionage campaign and Jewelbug’s financially motivated activity.

Cisco Talos 2026-09-30

Builds on: A hack-for-hire group hit 15+ government webmail tenants with one script tag, then escaped the…

threat02 Oct 04:50Zsingle-sourceOpen finding →
Sources: Cisco Talos

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • blog.talosintelligence.com1 (100%)