Skip to content

Security3 publishers2 min readPublished Updated

China-nexus UAT-11587 runs its Antino backdoor through Outlook and OneDrive

Cisco Talos links China-nexus UAT-11587 to 16 affected or targeted institutions in eight Asian countries, via a backdoor run through Microsoft 365. Its commands move through Outlook and OneDrive via Microsoft Graph, so defenders have no command server to block.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying China-nexus UAT-11587 runs its Antino backdoor through Outlook and OneDrive
Generated illustration

What happened

  • Talos first saw UAT-11587 activity in September 2025, aimed at government and policy bodies in countries including Taiwan, India, the Philippines and Cambodia.
  • The investigation began with a March 2026 spear-phish at Taiwan's academic, think tank and civil society policy community that mimicked Gmail's attachment interface.
  • The recurring delivery path runs from a spear-phishing email and a tailored decoy document into a five-stage infection chain.
  • Antino is a Rust-compiled Windows implant with reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence.
  • Ten distinct Antino builds contain Cargo registry paths pointing to rsproxy.cn, a Rust package mirror for faster downloads inside mainland China.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Once Antino is running, domain blocklists cannot cut its command traffic without also cutting the target's own Microsoft 365 service.
  • decision Hunting for Antino has to start on the endpoint, by asking which Windows processes call Microsoft Graph for Outlook and OneDrive objects and whether they have reason to.
  • contradiction Symantec puts a cryptocurrency-fraud SEO business in the access pipeline and Talos declines to, so the actor's resources and motive depend on whose boundary a defender adopts.

Talos calls the Outlook and OneDrive objects dead drops [6]. The operator leaves tasking in them and the implant collects it over Microsoft Graph. No dedicated command server sits in the path [5][6]. To a network team, the command stage looks like ordinary traffic to Microsoft 365 [2].

Talos's published material does not say whose Microsoft 365 accounts hold those objects: a tenant the actor registered, or accounts taken from victims. The answer determines which logs a defender would search.

The network indicators that do exist sit earlier in the chain. Cloudflare carried delivery, execution tracking and payload staging [8]. Entry, as Talos describes it, depends on a targeted person opening a lure written for them [7]. The lures follow a collection interest: Taiwanese political, legislative, civil defense and policy research subjects, plus regional government, maritime, diplomatic and security themes [18]. For organisations outside that profile, this actor is a low priority.

The operation is sustained. Talos has tracked it for about ten months, from September 2025 to July 2026 [1]. Over that span it saw several delivery methods, loader families and post-compromise tools [10].

Talos puts its China-nexus call at high confidence and says it rests on the totality of evidence, with no single indicator carrying it [11]. It is open about the weak pieces. UTC+8 covers mainland China, Taiwan, Hong Kong and Singapore [13]. A Taiwan-focused decoy also carried a zh-CN language tag and a Simplified Chinese author value meaning "undefined" [12]. Talos judges that combination more consistent with a mainland environment than with Taiwan or Hong Kong, where Traditional Chinese predominates [13].

Symantec published research on an activity set it calls Jewelbug while Talos was preparing its report, and Talos found overlaps with the Antino espionage [15]. Symantec reported that Jewelbug ran both espionage and cryptocurrency fraud [15]. It assessed that "the SEO business supplied access, delivery and infrastructure into the espionage operation, rather than that one person performed both roles" [16]. Talos could not independently verify a link between the espionage and the fraud. It tracks UAT-11587 as a separate activity set [17].

What to watch

  • Whether Talos or Microsoft says whose Microsoft 365 accounts hold Antino's dead drops: attacker-registered tenants, or accounts taken from victims.
  • Whether Talos and Symantec converge on the Jewelbug link between the cryptocurrency-fraud SEO business and the espionage operation.
  • New Antino builds, or confirmed victims beyond the eight countries Talos has counted so far.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories