GBHackers

China-Nexus Hackers Compromise 350 Systems Across Asia With New Antino Backdoor


A China-nexus cyber-espionage campaign that compromised approximately 350 endpoints across Asia using a previously undocumented Rust-based Windows backdoor called Antino.

The activity cluster, tracked as UAT-11587, targeted government, defense, diplomatic, policy, academic and civil-society organizations in at least eight countries between September 2025 and July 2026.

Talos identified 10 confirmed and five probable affected institutional environments, alongside one additional intended target.

Victims and targets were located in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria, with organizations involved in national security, foreign affairs, law enforcement, legislatures, e-government services, think tanks and universities particularly exposed.

The largest recorded wave occurred on June 8 and 9, 2026, when researchers observed about 57 newly identified endpoints associated with India.

UAT-11587 used highly tailored lures based on regional political developments, government administration, maritime policy, human rights, cross-strait issues and diplomatic events.

In one technique, the actor reproduced Gmail’s attachment-preview widget inside email HTML, creating a clickable attachment card designed to appear legitimate to recipients.

The phishing messages abused sender-domain misalignment to impersonate trusted entities.

The attackers sent mail through the Migadu service using their controlled osc-cdn[.]com domain as the SMTP envelope sender, while displaying an impersonated organization in the visible From field.

Although SPF passed for the attacker-controlled domain, DMARC alignment failed. Because the spoofed sender’s domain used a non-enforcing p=none policy, the message was still delivered to the victim’s inbox.

The attack chain begins when a recipient opens a malicious Cloudflare Pages link embedded in the fake attachment interface.

Timeline of UAT-11587 campaign activity (Source : Cisco Talos).

The link delivers an HTA or Windows Script Host stager that runs through mshta.exe or WSH, records execution telemetry and retrieves subsequent payloads from Cloudflare R2 or Amazon CloudFront.

A second-stage JScript downloader retrieves encrypted resources, applies custom Base64 decoding and RC4 decryption, then executes an in-memory .NET deserialization sequence.

Antino Backdoor

The attackers abuse BinaryFormatter and standard .NET gadget chains to load TestAssembly.dll directly inside the mshta.exe process.

Cisco Talos observed that, the campaign surfaced during an investigation into spear-phishing operations against Taiwan’s academic, think-tank and civil-society policy communities.

The actor replicated the styling of Gmail’s attachment card using four inline PNG images embedded as Base64-encoded MIME parts. 

Spear-phishing email sample (Source : Cisco Talos).
Spear-phishing email sample (Source : Cisco Talos).

The .NET component retrieves a decoy document and a DLL-sideloading bundle.

It launches the legitimate Microsoft-signed Windows ADK binary GatherOsState.exe, which sideloads a malicious adjacent slc.dll file containing Antino.

This use of a signed Windows binary reduces suspicion and can complicate endpoint detection.

Antino is available as both a standalone executable and DLL, with 32-bit and 64-bit builds.

It provides host reconnaissance, command-shell and PowerShell execution, directory enumeration, file upload and download, in-memory shellcode loading, and Registry Run-key persistence.

The Windows application manifest identifies the program as AntinoApp (Source : Cisco Talos).
The Windows application manifest identifies the program as AntinoApp (Source : Cisco Talos).

Its most notable feature is its command-and-control architecture. Rather than communicate with a conventional external C2 server, Antino uses Microsoft Graph API calls to interact exclusively with attacker-controlled Outlook and OneDrive resources.

The malware authenticates through an Entra ID application using the OAuth 2.0 client-credentials flow, allowing it to communicate through trusted Microsoft 365 services without an interactive login.

The implant uploads heartbeat telemetry to OneDrive every minute, including the machine name, username, platform, session identifier and campaign information.

It also uses OneDrive folders to receive tools and upload stolen data. For tasking, Antino polls an Outlook mailbox every 10 seconds for messages named command_req_[session_id] and sends results through corresponding command_res_[session_id] messages.

This dead-drop model allows malicious traffic to blend with ordinary Microsoft 365 synchronization activity directed to graph.microsoft.com and login.microsoftonline.com, making network-only detection substantially harder.

Talos assessed with high confidence that UAT-11587 is China-nexus based on converging operational and technical indicators.

These include Simplified Chinese metadata in Taiwan-focused decoys, UTC+8 timestamps, repeated references to the mainland China-focused Rust package mirror rsproxy.cn, and victimology consistent with regional intelligence collection.

Talos also found limited infrastructure overlap with activity previously associated with China-nexus UNC6384, although it rated that connection as low confidence.

Defenders should investigate unusual mshta.exe or WSH activity reaching Cloudflare Pages, R2 or CloudFront; Microsoft-signed GatherOsState.exe instances loading locally placed slc.dll; suspicious Graph API activity involving unfamiliar Entra applications; and OneDrive paths resembling /antino/heartbeats/, /antino_uploads/ or /antino_downloads/.

Talos released ClamAV signatures and Snort rules 66880–66882 for detection, while its published IOC repository contains hashes for malicious HTA, WSF, JScript and serialized loader components.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link