> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel

[SOURCE] Security Affairs [AUTHOR: Pierluigi Paganini] [DATE: 03/10/2026 09:26] [LANGUAGE: EN]
Cisco Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments. Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight Asian countries. The toolset includes a previously undocumented backdoor Talos named Antino, and the thing that makes it worth paying attention to isn’t how it gets in. It’s where it hides once it’s there. Antino is written in Rust and works on both 32-bit and 64-bit versions of Windows. It supports the usual backdoor features, including shell and PowerShell access, file transfers, in-memory shellcode execution and persistence. “Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence. Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.” reads the report published by Talos. None of these features are particularly new. What makes Antino different is how it communicates: instead of using its own command-and-control server, it uses Microsoft Graph to read commands from an Outlook mailbox and send stolen files to OneDrive. This allows its traffic to blend in with normal Microsoft 365 activity. The attack starts in a more traditional way, with a convincing phishing email. UAT-11587 created highly targeted documents that suggest the attackers had researched their victims, including a fake workshop document about Taiwan’s information warfare and a document that closely copied a real Taiwan Ministry of Finance ruling about tax treatment for legislators. “The document exactly reproduces a public Taiwan Ministry of Finance ruling to make the decoy appear credible.” conctinues the report. “Its subject strongly suggests that it was prepared for members of Taiwan’s public sector.” In another case, the attackers reused a real Associated Press story about alleged Russian offers to the US over Venezuela. Matching malware samples appeared on VirusTotal two days after the original article was published. The delivery trick is a simple but effective email spoofing technique that takes advantage of a gap many people overlook. The attackers sent the email through a legitimate provider, using one domain as the technical sender, while the visible From address showed the organization they were impersonating. SPF passed because the real sending domain was authorized, but DMARC detected the mismatch and failed. That still wasn’t enough to block the message. The impersonated domain had a DMARC policy set to monitoring rather than rejection, so the failed email still reached the inbox. The Gmail trick is even more interesting. The attackers recreated Gmail’s normal attachment preview card almost pixel by pixel using images embedded in the email’s HTML. They then made the fake preview a link to a page controlled by the attackers. Open the email in Gmail and it looks just like the real thing because Gmail simply renders the HTML it receives. There is no exploit here. It’s just a very convincing copy of something users already trust. From that click, a five-stage chain kicks in, leaning on legitimate-looking HTA files, Windows Script Host, and a scripted .NET deserialization trick that abuses a known gadget chain to load malicious code inside a trusted process. The final stage sideloads Antino through a signed Microsoft diagnostic binary, meaning the thing dropping the backdoor onto disk is a tool Windows itself trusts by default. Cloudflare Pages, R2, and Amazon CloudFront carried almost every stage of this, which kept the traffic blending into ordinary HTTPS the whole way through. Once Antino is running, it checks its Outlook mailbox for new commands every ten seconds. The commands and results are sent as structured JSON hidden inside specially formatted email subjects. “The Antino backdoor receives commands through email messages. The implant actively pulls commands from the threat actor’s Outlook mailbox folder every 10 seconds. The protocol uses two message types: command emails contain tasking from the controller, while response emails contain the implant’s results.” states Talos. “Command messages are identified by the subject prefix command_req_[session_id] and responses by command_res_[session_id], as indicated in the HTTP GET request sent by Antino: “ A separate system is used to upload stolen files to one OneDrive folder and download attacker tools from another. Even the naming makes the attacker’s perspective clear: “uploads” are files sent to the victim, while “downloads” are files pulled back from the victim. The attribution case leans on accumulated small details rather than any single smoking gun, which is honestly how these assessments should work. Decoy document metadata carries Simplified Chinese language tags and a UTC+8 timestamp, a combination more consistent with mainland China than Taiwan or Hong Kong, where Traditional Chinese dominates. Separately, ten different Antino builds reference a Rust package mirror built specifically to speed up dependency downloads inside mainland China, the kind of tooling choice a developer picks for convenience, not for disguise. The victim list reads like a checklist of what an intelligence service would actually want: defense ministries, legislatures, foreign affairs offices, border and interior security agencies, plus the think tanks and civil society groups that tend to know things governments care about early. Around 350 compromised endpoints turned up across eight countries, with the largest single wave, roughly 57 new endpoints, hitting India over two days in June. That’s not noise. That’s a deliberate and sustained collection effort. “Based on the development, preparation-environment, and targeting indicators detailed in this report, Talos assesses with high confidence that UAT-11587 is China-nexus.” the report concludes. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, Antino backdoor)
[messages.read_original_source] →