# China-Nexus UAT-11587 Targets Asian Government and Policy Organizations With Antino Backdoor
Cisco Talos has identified a China-nexus threat activity cluster targeting government and policy organizations across Asia with a previously undocumented Windows backdoor called **Antino**.
Tracked as **UAT-11587**, the campaign has targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. Talos first observed the activity in September 2025 and identified at least 16 affected or targeted institutional environments across eight Asian countries. The investigation also identified approximately 350 compromised endpoints.
## UAT-11587 Targets Government and Security Organizations
The campaign primarily focuses on government and national-security-related organizations.
Targeted sectors include:
- Defense, military, and national security
- Executive government and public administration
- Foreign affairs and diplomatic services
- Justice and law enforcement
- Border and interior security
- Legislative and parliamentary organizations
- Government IT and shared e-government services
- Universities and research institutions
- Think tanks
- Civil society and public policy organizations
Talos assesses with moderate-to-high confidence that organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria were targeted.
The targeting and the capabilities of the malware are consistent with an intelligence-gathering operation, according to Talos.
## China-Nexus Assessment
Talos assesses with high confidence that UAT-11587 is China-nexus based on multiple technical and operational indicators.
Some Antino samples contain development paths referencing **rsproxy[.]cn**, a Rust package mirror intended to improve dependency downloads within mainland China.
Researchers also found Simplified Chinese metadata and `zh-CN` language settings in lure documents. Recovered phishing messages contained a **UTC+08:00** time offset.
Talos noted that UTC+08:00 by itself is not geographically distinctive because it is used in several countries and regions. However, the combination of the time zone, Simplified Chinese metadata, language settings, targeting patterns, and development artifacts contributed to the attribution assessment.
## Possible Infrastructure Overlap With UNC6384
Talos identified a JavaScript downloader associated with UAT-11587 that referenced:
`d32tpl7xt7175h[.]cloudfront[.]net`
The CloudFront infrastructure had previously been reported by Arctic Wolf in connection with China-nexus activity attributed to **UNC6384**.
Talos considers this relationship low confidence because cloud infrastructure can be reused and the two campaigns use different malware and command-and-control architectures.
## Relationship With Jewelbug
Talos also identified some overlap between UAT-11587 and the activity tracked as **Jewelbug**.
However, researchers could not independently establish a connection between the espionage activity involving Antino and Jewelbug's financially motivated cryptocurrency operations.
As a result, Talos continues to track UAT-11587 as a separate activity cluster.
## Spear-Phishing Used for Initial Access
UAT-11587 frequently uses targeted spear-phishing emails to deliver malware.
The phishing messages were tailored to the interests and responsibilities of specific organizations and individuals.
Lure themes included:
- Foreign affairs
- International security
- Government policy
- Defense
- Diplomatic activity
- Regional geopolitical issues
The targeting suggests that the attackers conducted reconnaissance before creating the phishing material.
## Fake Gmail Attachment Preview
One of the campaign's notable techniques involves recreating Gmail's attachment preview interface inside an email.
The attackers used HTML and Base64-encoded PNG images to reproduce the appearance of a legitimate Gmail attachment card.
The fake attachment interface was then wrapped in a link pointing to an attacker-controlled Cloudflare Pages URL.
When opened in Gmail, the email rendered the malicious HTML and displayed a convincing attachment preview, increasing the likelihood that the recipient would click it.
## Five-Stage Attack Chain
Talos identified a recurring five-stage infection chain that ultimately delivers Antino.
### Stage 1: Phishing Email
The victim receives a targeted email containing a malicious link or a fake attachment preview.
### Stage 2: HTA or WSF File
The Cloudflare URL redirects the victim to an HTA or WSF file.
The file acts as the initial stager and retrieves the next payload.
### Stage 3: JavaScript Downloader
The stager downloads a JavaScript downloader and decryptor.
The next stage uses a .NET deserialization chain to load `TestAssembly.dll`.
### Stage 4: .NET Downloader
`TestAssembly.dll` performs three primary actions:
- Opens the lure document for the victim
- Downloads a decoy Calculator executable
- Downloads and launches the Antino backdoor
### Stage 5: Antino Deployment
The final payload is stored as `slc.dll`.
It is loaded through DLL sideloading using the legitimate Microsoft-signed `GatherOsState.exe` binary.
Once loaded, Antino establishes communication through Microsoft 365 services.
## Antino Backdoor Capabilities
Antino is a **Rust-compiled Windows backdoor** designed to provide attackers with persistent remote access.
Its capabilities include:
- Host reconnaissance
- Process enumeration
- Directory enumeration
- Shell command execution
- PowerShell execution
- File transfer
- Shellcode loading in memory
- Execution of attacker-supplied programs
- Persistence
- Remote command execution
The malware can execute commands through `cmd.exe`, run PowerShell scripts, load shellcode, and interact with files and directories.
## Microsoft 365 Used as Command and Control
A key feature of Antino is its use of legitimate Microsoft 365 services for command and control.
Instead of connecting to a dedicated C2 server, the malware communicates with Microsoft 365 through **Microsoft Graph**.
It uses:
- **Outlook for command exchange**
- **OneDrive for heartbeat communication**
- **OneDrive for file transfer**
Antino checks an Outlook mailbox approximately every 10 seconds for commands.
The malware searches for messages using a subject format similar to:
`command_req_[session_id]`
This technique allows the malware to hide its communications within commonly used Microsoft 365 services.
## Abuse of Legitimate Windows Components
Antino also abuses the **Windows Scripted Diagnostics framework** to execute attacker-controlled PowerShell through legitimate Windows components.
This can make it more difficult to associate PowerShell activity directly with the malware.
However, the technique still leaves potential detection opportunities through:
- PowerShell telemetry
- File creation events
- Registry activity
- Process execution
- Microsoft 365 network activity
## Campaign Timeline
Talos observed UAT-11587 activity from **September 2025 through July 2026**.
The earliest activity used Philippines-themed lures and direct email attachments.
In January 2026, the attackers conducted additional Philippines-focused HTA campaigns and expanded their lure themes to broader political and geopolitical topics.
Activity increased between March and early June 2026.
The largest concentrated wave occurred on **June 8 and 9**, when Talos identified approximately 57 newly observed endpoints associated with India.
The campaign subsequently showed activity involving Cambodia, Myanmar, Syria, Pakistan, and Thailand.
## Conclusion
UAT-11587 combines targeted spear-phishing, multi-stage malware delivery, DLL sideloading, and Microsoft 365-based command and control to maintain access to government and policy organizations.
The **Antino** backdoor provides capabilities for reconnaissance, command execution, PowerShell activity, file transfers, shellcode execution, and persistence.
Its use of **Microsoft Graph, Outlook, and OneDrive** instead of a conventional dedicated C2 server is a significant part of the campaign's infrastructure design.
Cisco Talos assesses UAT-11587 as China-nexus with high confidence while continuing to track it separately from Jewelbug because the available evidence does not establish a direct connection between the espionage campaign and Jewelbug's financially motivated activity.