Security3 publishers2 min readPublished Updated
China-nexus UAT-11587 runs its Antino backdoor through Outlook and OneDrive
Cisco Talos links China-nexus UAT-11587 to 16 affected or targeted institutions in eight Asian countries, via a backdoor run through Microsoft 365. Its commands move through Outlook and OneDrive via Microsoft Graph, so defenders have no command server to block.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Talos first saw UAT-11587 activity in September 2025, aimed at government and policy bodies in countries including Taiwan, India, the Philippines and Cambodia.
- The investigation began with a March 2026 spear-phish at Taiwan's academic, think tank and civil society policy community that mimicked Gmail's attachment interface.
- The recurring delivery path runs from a spear-phishing email and a tailored decoy document into a five-stage infection chain.
- Antino is a Rust-compiled Windows implant with reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence.
- Ten distinct Antino builds contain Cargo registry paths pointing to rsproxy.cn, a Rust package mirror for faster downloads inside mainland China.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Once Antino is running, domain blocklists cannot cut its command traffic without also cutting the target's own Microsoft 365 service.
- decision Hunting for Antino has to start on the endpoint, by asking which Windows processes call Microsoft Graph for Outlook and OneDrive objects and whether they have reason to.
- contradiction Symantec puts a cryptocurrency-fraud SEO business in the access pipeline and Talos declines to, so the actor's resources and motive depend on whose boundary a defender adopts.
Talos calls the Outlook and OneDrive objects dead drops [6]. The operator leaves tasking in them and the implant collects it over Microsoft Graph. No dedicated command server sits in the path [5][6]. To a network team, the command stage looks like ordinary traffic to Microsoft 365 [2].
Talos's published material does not say whose Microsoft 365 accounts hold those objects: a tenant the actor registered, or accounts taken from victims. The answer determines which logs a defender would search.
The network indicators that do exist sit earlier in the chain. Cloudflare carried delivery, execution tracking and payload staging [8]. Entry, as Talos describes it, depends on a targeted person opening a lure written for them [7]. The lures follow a collection interest: Taiwanese political, legislative, civil defense and policy research subjects, plus regional government, maritime, diplomatic and security themes [18]. For organisations outside that profile, this actor is a low priority.
The operation is sustained. Talos has tracked it for about ten months, from September 2025 to July 2026 [1]. Over that span it saw several delivery methods, loader families and post-compromise tools [10].
Talos puts its China-nexus call at high confidence and says it rests on the totality of evidence, with no single indicator carrying it [11]. It is open about the weak pieces. UTC+8 covers mainland China, Taiwan, Hong Kong and Singapore [13]. A Taiwan-focused decoy also carried a zh-CN language tag and a Simplified Chinese author value meaning "undefined" [12]. Talos judges that combination more consistent with a mainland environment than with Taiwan or Hong Kong, where Traditional Chinese predominates [13].
Symantec published research on an activity set it calls Jewelbug while Talos was preparing its report, and Talos found overlaps with the Antino espionage [15]. Symantec reported that Jewelbug ran both espionage and cryptocurrency fraud [15]. It assessed that "the SEO business supplied access, delivery and infrastructure into the espionage operation, rather than that one person performed both roles" [16]. Talos could not independently verify a link between the espionage and the fraud. It tracks UAT-11587 as a separate activity set [17].
What to watch
- Whether Talos or Microsoft says whose Microsoft 365 accounts hold Antino's dead drops: attacker-registered tenants, or accounts taken from victims.
- Whether Talos and Symantec converge on the Jewelbug link between the cryptocurrency-fraud SEO business and the espionage operation.
- New Antino builds, or confirmed victims beyond the eight countries Talos has counted so far.