A Rust-built implant that takes its orders from Outlook mailboxes and stores its loot in OneDrive has been working against Asian government and policy targets for a year.
Intelligence Lead
Cisco Talos has exposed a China-nexus espionage cluster, tracked as UAT-11587, that runs its Antino backdoor with no conventional command-and-control server at all: tasking, status reporting and exfiltration all move through Microsoft 365. The campaign is assessed with high confidence to serve Chinese state intelligence collection on Indo-Pacific policy, and its design means defenders cannot simply block the channel without cutting off legitimate business traffic.
Situation Report
Talos reported that Antino is a Rust-compiled Windows backdoor supporting host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence. It authenticates to Microsoft Graph using Entra ID application credentials, so no interactive user login is required. According to reporting on the Talos findings, the implant polls an attacker-controlled Outlook mailbox for commands roughly every 10 seconds and returns results through the same channel. OneDrive handles implant registration, status updates sent about every 60 seconds, stolen files and additional operator tools.
Delivery relies on tailored spear-phishing. Researchers documented spoofed sender authentication that bypassed SPF and DMARC checks, HTML lures carrying fake Gmail attachment widgets, and a five-stage chain running from an HTA or WSF stager through a JavaScript downloader and .NET deserialization to DLL sideloading via a legitimate Microsoft binary. Persistence abuses Windows troubleshooting components, including sdiagnhost.exe and sdiageng.dll, to launch PowerShell at startup.
Lure themes track regional security agendas: Indo-Pacific policy, the Bajo de Masinloc maritime dispute, Taiwanese legislative taxation, bilateral summits and seminars on cross-border repression. Targets span government, defence, diplomatic, academic, think-tank and civil-society organisations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. Reporting cites roughly 350 compromised endpoints and 10 confirmed institutional environments, with further probable victims. Outlets differ on the precise entity count, which ranges between 15 and 16.
Background & Context
The earliest activity was identified in September 2025 in a spear-phishing campaign against Taiwan. Tempo rose between March and early June 2026, with a concentrated wave on 8 and 9 June. Syrian targeting was observed in May 2026, a geographic outlier relative to the Indo-Pacific focus of most lures.
Attribution rests on several independent indicators: Simplified Chinese language settings and metadata in lure documents, UTC+08:00 timestamps in message headers, development artifacts referencing the rsproxy.cn Cargo mirror hosted in mainland China, and CloudFront infrastructure overlapping with the China-affiliated cluster UNC6384. Talos noted a possible connection to the group known as Jewelbug but did not confirm it, and rated relationships suggested by shared delivery infrastructure as low confidence.
The disclosure lands in the same week as MI5's public warning over the China General Technology Research Institute and Proofpoint's reporting on TA419 impersonation of AI policy figures. Taken together, the three releases describe Chinese collection operations working simultaneously through funding channels, social engineering and cloud-native tooling against the policy ecosystems that shape Western and regional decision-making.
Analysis & Assessment
The central assessment is that UAT-11587 has treated Microsoft 365 as operational infrastructure rather than as an intrusion vector. Command traffic to Graph endpoints from a tenant already trusted by the victim resembles routine mail and file synchronisation, which strips defenders of the indicators they normally rely on: rogue domains, unfamiliar IP addresses and beaconing to known-bad hosts. Cloud-API command-and-control is an established tradecraft trend among capable state actors. Antino is a clean, fully operational example of it directed at under-defended policy organisations.
The collection requirement is assessed with moderate confidence to be strategic intent rather than technology theft. Lure themes concentrate on Taiwan, South China Sea disputes and Indo-Pacific diplomacy, which are the questions on which Beijing most needs advance sight of neighbouring governments' positions. The Syrian cluster is the exception. It suggests tasking beyond the immediate neighbourhood, though a single month of observed activity is too thin to say whether that reflects a standing requirement.
The Jewelbug and UNC6384 overlaps carry an alternative reading that matters for defenders: shared tooling or procurement across several China-nexus teams, not one unified operator. That possibility cannot be ruled out. It would mean Antino-style techniques spread quickly once published, and that organisations outside Asia should treat the tradecraft as portable.