# New China-Nexus Backdoor “Antino” Targets Government Organizations Across Asia Using Microsoft 365 as Covert C2 Channel
A sophisticated cyber espionage campaign has emerged, focusing on government and policy institutions throughout Asia, leveraging a never-before-seen malware strain known as Antino. The threat cluster, tracked under the designation UAT-11587, has been linked to a China-aligned adversary with deep expertise in social engineering and infrastructure abuse.
## Scope of the Campaign
Since first emerging in September 2025, the operation has expanded to compromise entities across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, with evidence suggesting additional targeting of organizations in Syria by mid-2026. The campaign’s peak activity occurred between March and early June 2026, with a concentrated offensive on June 8 and 9, 2026, striking dozens of systems tied to government IT infrastructure.
## Technical Profile of the Antino Backdoor
Antino is a sophisticated piece of malware written in the Rust programming language and compiled for the Windows operating system. Once deployed on a victim’s machine, the backdoor provides its operator with an extensive toolkit:
– **Host reconnaissance** — scanning running processes, enumerating directories, and mapping the compromised system’s environment
– **Command execution** — launching PowerShell scripts, shellcode, operator-supplied programs, and arbitrary shell commands via cmd.exe
– **File transfer** — enabling the movement of data in and out of the compromised host
– **In-memory shellcode loading** — allowing execution of additional payloads without touching the disk
– **Persistence mechanisms** — ensuring the malware survives system reboots
What makes Antino particularly notable is its command-and-control architecture. Rather than communicating through a traditional, easily detectable C2 server, the backdoor exclusively leverages Microsoft 365 services. It uses Microsoft Graph APIs to interact with Outlook and OneDrive, turning these legitimate business tools into covert communication channels. Commands are retrieved from the attacker’s Outlook mailbox folder by polling for messages with a specific subject line format every 10 seconds, while OneDrive serves as both a heartbeat mechanism and a file transfer medium.
## The Attack Chain
The intrusion follows a carefully constructed five-stage process:
**Stage 1 — Initial Delivery:** The campaign begins with a spear-phishing email. The attackers have been observed spoofing sender identities trusted by the intended recipients, allowing them to circumvent SPF and DMARC authentication checks. To further deceive targets, the phishing emails feature a meticulously reconstructed Gmail attachment preview widget embedded directly in the HTML body, using Base64-encoded PNG images that replicate the styling of a legitimate Gmail interface. A Cloudflare Pages URL hidden within the widget tricks the recipient into downloading the malicious payload.
**Stage 2 — Stager Execution:** The downloaded file, either an HTA or WSF file, is executed and serves as the initial stager that retrieves a JavaScript downloader and decryptor.
**Stage 3 — .NET Deserialization:** The second stage triggers a .NET deserialization chain that loads a malicious assembly called “TestAssembly.dll.” This .NET downloader and launcher performs three simultaneous actions — opening a decoy lure document to maintain the victim’s trust, downloading a benign-looking Calculator executable, and downloading the Antino backdoor itself.
**Stage 4 — DLL Sideloading:** The core implant file (slc.dll) is launched through DLL sideloading, a technique that abuses a legitimate Microsoft-signed binary called “GatherOsState.exe” to load the malicious library into memory. This approach helps the malware blend in with normal system activity.
**Stage 5 — C2 and Operations:** Once active, Antino communicates through Outlook and OneDrive, using the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components, further obscuring its activity.
## Attribution to China
Security analysts have assigned high confidence to a China-nexus attribution based on several converging indicators. The lure documents contain zh-CN language settings and Simplified Chinese metadata, while the spear-phishing message headers reveal timestamps set to the UTC+08:00 time zone, corresponding to China Standard Time. Additionally, the malware builds reference rsproxy[.]cn, a high-speed domestic mirror and proxy service for the Rust Cargo registry catering specifically to mainland China developers.
The targeting pattern reinforces this assessment, with lures and victims centered on Taiwanese political and legislative entities, civil defense organizations, policy research institutions, and regional government, maritime, diplomatic, and security subjects — all areas of strategic interest to Chinese state-affiliated operations.
The campaign has also been linked to a broader cluster of threat activity, with some overlap observed with a group tracked as Jewelbug. However, researchers emphasize that UAT-11587 operates as a distinct activity set, separate from Jewelbug’s financially motivated cryptocurrency fraud operations.
## Why This Matters
The Antino campaign represents a significant evolution in how state-sponsored threat actors leverage cloud services for espionage. By using Microsoft 365 as the sole C2 infrastructure, the attackers minimize their exposure to network monitoring tools and security analytics that typically flag dedicated command-and-control servers. The use of DLL sideloading, combined with abuse of legitimate Windows diagnostic frameworks, further complicates detection and forensic analysis.
The campaign’s focus on policy and diplomatic targets across multiple countries suggests a strategic intelligence-gathering objective aimed at understanding regional governments’ positions and operations.
—
## Frequently Asked Questions (FAQ)
**What is Antino?**
Antino is a Rust-compiled Windows backdoor that provides remote access to compromised systems, enabling reconnaissance, command execution, file transfer, and persistence. It was identified as part of a broader espionage campaign tracked as UAT-11587.
**Which organizations are being targeted?**
The campaign primarily focuses on government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, with evidence of targeting organizations in Syria as well. Specific sectors include political institutions, legislative bodies, civil defense agencies, think tanks, maritime organizations, diplomatic entities, and security-related government infrastructure.
**How does Antino communicate with its operators?**
Antino exclusively uses Microsoft 365 services for command and control. It communicates through Outlook for command exchange and OneDrive for heartbeat signals and file transfers, rather than relying on traditional dedicated C2 servers.
**What makes this campaign different from other espionage operations?**
The exclusive reliance on Microsoft 365 as C2 infrastructure, combined with the use of DLL sideloading and abuse of the Windows Scripted Diagnostics framework, makes Antino particularly stealthy and difficult to detect through conventional security monitoring.
**How does the initial phishing attack work?**
The attackers send spear-phishing emails that spoof trusted sender identities and include a reconstructed Gmail attachment preview widget embedded in the email HTML. When the target interacts with the fake attachment, it downloads a malicious payload from a Cloudflare Pages-hosted URL.
**Is there a connection between this campaign and Jewelbug?**
While there is some overlap between UAT-11587 and Jewelbug in terms of tactics and infrastructure, researchers have identified them as separate activity sets. Jewelbug is characterized by both espionage and financially motivated cryptocurrency fraud, whereas UAT-11587 appears focused exclusively on intelligence operations.
**How can organizations defend against this threat?**
Organizations should implement robust email security controls including advanced attachment inspection, enforce strict DMARC policies, train employees to recognize social engineering tactics, monitor for anomalous Microsoft 365 API usage, and deploy endpoint detection capabilities that can identify DLL sideloading and misuse of Windows diagnostic frameworks.
—
## Conclusion
The Antino backdoor campaign underscores the growing sophistication of China-nexus cyber espionage operations targeting the Asia-Pacific region. By weaponizing trusted cloud services like Microsoft 365 and employing advanced social engineering techniques, the threat actor behind UAT-11587 has crafted an operation that is both highly targeted and exceptionally difficult to detect. The campaign’s focus on policy and governmental institutions signals a strategic intent to gather intelligence on regional diplomatic, security, and legislative matters. As this threat continues to evolve, organizations across the targeted sectors must prioritize layered defenses, enhanced email security, and proactive threat hunting to identify and neutralize these advanced intrusions before they can achieve their objectives.
Thank you for reading



