Skip to content

Talos: China-nexus UAT-11587 hits Asian governments with Antino

Cisco Talos ties China-nexus UAT-11587 to spear-phishing on 16 government and policy targets across 8 Asian countries, deploying the Rust 'Antino' backdoor via M365 dead drops.

Published 3 min read

Cisco Talos has detailed a cyber-espionage campaign it tracks as UAT-11587, assessed "with high confidence" to be China-nexus, that compromised at least 16 institutional environments across eight Asian countries and deployed a Rust-based Windows backdoor Talos calls Antino. By July 2026, Talos counted roughly 350 compromised endpoints.

Attribution — as Talos frames it

Talos's China-nexus assessment rests on development and operational artifacts, not a government indictment: Simplified Chinese language tags, UTC+8 build timestamps, references to rsproxy.cn (a China-focused Rust package mirror), and targeting that aligns with Chinese intelligence interests. Keep that framing — this is Talos's high-confidence attribution of a cluster (UAT- = unattributed threat), not an officially attributed state actor.

Who was hit

Talos lists targets across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria, spanning defense and military, executive government, foreign affairs, justice and border security, legislatures, government IT, plus think tanks, universities, and civil-society and human-rights organizations. Activity ran September 2025 through July 2026, accelerating March–June 2026; the largest single wave was June 8–9, when ~57 new India-focused endpoints appeared.

The infection chain and Antino

Initial access came via spear-phishing with cloned Gmail attachment widgets pointing to Cloudflare Pages URLs that hosted a five-stage chain: HTA/WSF stagers, a JScript downloader with RC4 decryption, a .NET BinaryFormatter deserialization gadget chain, a TestAssembly.dll loader, and finally DLL sideloading of Antino through the legitimate, Microsoft-signed GatherOsState.exe.

Antino (Rust, Windows) supports host reconnaissance, command and PowerShell execution, file transfer, in-memory shellcode loading with sleep-mask evasion, and persistence via Registry Run keys. Its C2 is notable: it uses Microsoft 365 — Outlook and OneDrive — as dead drops, blending command traffic into sanctioned cloud services.

Indicators of compromise

Published by Talos (verbatim):

# Domains
osc-cdn[.]com
microsoft-flash[.]com
wps-cn[.]com
d2nq35tel3ucuo[.]cloudfront[.]net
pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev
oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev

# SHA-256
e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34  # HTA stager
09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff  # Antino Gen 2
1fadc90b61ce536abda78eb387a7f3d745f00c16775d3f762845ccc0fde567da  # Antino Gen 1

Action checklist

  1. Hunt the hashes and domains above across EDR and proxy/DNS logs; the Cloudflare Pages and R2 infrastructure is disposable, so prioritize the file hashes.
  2. Flag GatherOsState.exe loading a non-system DLL — this signed-binary sideload is the delivery sink for Antino.
  3. Watch M365 as a C2 surface. Look for anomalous Outlook/OneDrive automation on endpoints that shouldn't be driving Graph/API traffic; dead-drop C2 won't trip network egress rules pointed only at odd domains.
  4. Alert on the chain markers: HTA/WSF execution from browser-download paths and BinaryFormatter deserialization in .NET processes.

Context

The tradecraft here is mundane where it counts — spear-phishing, signed-binary sideloading, cloud-service dead drops — and that's the point: UAT-11587 spends its novelty on a Rust backdoor and M365-blended C2 while leaning on living-off-trusted-infrastructure for everything else. For defenders in the targeted sectors, the detections that matter are behavioral (sideloading, deserialization, out-of-pattern M365 automation), not a domain blocklist that the actor can rebuild in an afternoon.

Related stories