A sophisticated cyber espionage campaign, attributed to a China-linked threat actor, is targeting government and policy organizations throughout Asia by deploying a novel backdoor called Antino. This malware uses Microsoft 365 tools like Outlook and OneDrive for command-and-control operations, raising concerns across the region.
Antino Backdoor and Its Targets
The Antino backdoor was detected as part of a spear-phishing operation initially aimed at Taiwan’s academic and policy sectors in September 2025. Since then, it has expanded its scope to infiltrate 16 entities across eight countries including India, the Philippines, and Thailand. The campaign, tracked by Cisco Talos as UAT-11587, employs the Rust-compiled Antino malware, capable of conducting host reconnaissance, executing commands, and maintaining persistence.
Antino’s reliance on Microsoft 365 involves using Microsoft Graph to communicate through Outlook and OneDrive, avoiding conventional command-and-control servers that are easier to detect. This strategy complicates efforts to trace the origin of attacks while allowing continuous data exchange with compromised networks.
Links to Other Threat Actors
Although UAT-11587 shares tactical similarities with other China-aligned groups such as Jewelbug, Cisco Talos has not confirmed any direct financial motivations linking the two. Jewelbug has been identified by Symantec and Carbon Black as a group engaging in both espionage and cryptocurrency fraud. Despite these connections, UAT-11587 is classified as a distinct entity, focusing primarily on espionage activities.
Evidence pointing to a China nexus includes Simplified Chinese metadata in phishing documents and tactics consistent with Chinese cyber operational interests. The campaign’s targets align with those typically pursued by China-based actors, focusing on political and governmental entities.
Technical Insights and Social Engineering
The Antino backdoor is notable for its exploitation of the Windows Scripted Diagnostics framework to run PowerShell commands discreetly. This method complicates the ability to attribute activities directly to the malware. Additionally, the group has employed sophisticated social engineering tactics, such as mimicking Gmail’s attachment preview to deceive recipients.
UAT-11587’s spear-phishing emails are carefully crafted, often impersonating trusted senders to bypass email security protocols like SPF and DMARC. The attack chain consists of multiple steps, from downloading a JavaScript decryptor to loading the Antino malware, ultimately using legitimate Microsoft-signed binaries for stealthy operations.
Implications and Future Outlook
This campaign underscores the evolving nature of cyber threats, where state-linked actors leverage legitimate platforms to conduct stealthy operations. The use of common platforms like Microsoft 365 highlights the necessity for organizations to enhance their cybersecurity measures, particularly in sectors vulnerable to state-sponsored espionage.
As this campaign unfolds, affected regions must remain vigilant and adapt to the dynamic threat landscape. Organizations are encouraged to bolster their security postures, focusing on email security and advanced threat detection to mitigate such sophisticated attacks.
