CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
NOTABLENATOB2threat

UAT-11587: a China-nexus cluster spear-phishes Asian government and policy bodies with Antino, a Rust backdoor whose only command channel is Microsoft 365 through Microsoft Graph

Talos: Antino's traffic ends only at Microsoft's Graph and login endpoints, so network telemetry shows only Microsoft

Analysis

Cisco Talos tracks UAT-11587, first seen in September 2025, with at least 10 confirmed and five probable affected institutional environments and about 350 compromised endpoints across eight countries (Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria, listed at moderate-to-high confidence); the targets include defense, central administration, justice and law enforcement, government IT and e-government services, legislatures and policy research bodies (Cisco Talos, 2026-09-30). Talos assesses China-nexus with high confidence and intelligence gathering with moderate confidence, and notes overlaps with the Antino activity Symantec attributes to Jewelbug without being able to verify a link to Jewelbug's financially motivated activity (Cisco Talos, 2026-09-30).

Delivery is spear-phishing in which the envelope sender is an attacker-controlled domain relayed through Migadu while the visible From header shows the impersonated organization, so SPF passes for the envelope domain, DMARC alignment fails, and a p=none policy on the impersonated domain lets the message reach the inbox; the mail body reproduces Gmail's attachment widget as images linking to a Cloudflare Pages address (Cisco Talos, 2026-09-30). The five-stage chain starts with an HTA stager run by mshta.exe, then a JScript downloader and decryptor that pulls encrypted resources from Cloudflare R2 or CloudFront, then .NET deserialization gadgets that load a downloader assembly inside mshta.exe, which writes a decoy and a three-file bundle and launches the Microsoft-signed Windows ADK binary GatherOsState.exe; that binary sideloads an unexpected DLL, which is Antino (Cisco Talos, 2026-09-30).

Antino is a Rust backdoor whose second-generation build authenticates to Microsoft Graph with the OAuth 2.0 client-credentials flow of an Entra application, polls an Outlook folder every 10 seconds for command emails, sends a OneDrive heartbeat every minute and uses OneDrive folders for tool staging and exfiltration, so outbound traffic ends only at graph.microsoft.com and login.microsoftonline.com (Cisco Talos, 2026-09-30). Its commands run cmd.exe and PowerShell, list, upload and download files, load shellcode in memory and add a registry Run value; execution and persistence abuse the Windows Scripted Diagnostics workflow, in which sdiagnhost.exe runs an attacker-written PowerShell script that writes the HKCU Run value (Cisco Talos, 2026-09-30).

Exposure: mail recipients whose organization's domain publishes DMARC p=none (the policy that let the reviewed message through), and endpoints where mshta.exe and Windows Script Host can run; Talos names no European victim.

Triage: Microsoft Graph traffic and signed Windows ADK binaries are both normal; the signal is the combination of GatherOsState.exe running from a staging directory outside the Windows ADK install, beside an unexpected DLL and that process then holding Graph connections.

Cited evidence

Antino communicates exclusively through Microsoft 365, using the Microsoft Graph API to interact with Outlook and OneDrive as dead-drop C2 channels.

In the reviewed message, the displayed domain used a non-enforcing p=none policy, which requested monitoring rather than quarantine or rejection.

Talos could not independently verify a connection between the espionage campaign and Jewelbug’s financially motivated activity.

Cisco Talos 2026-09-30

Sources1

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.