News Room
16
Share
China-Nexus UAT-11587 Deploys 'Antino' Backdoor via Microsoft 365 Infrastructure
highCyber Espionage

China-Nexus UAT-11587 Deploys 'Antino' Backdoor via Microsoft 365 Infrastructure

A new China-linked espionage campaign targeting Asian government entities utilizes the novel 'Antino' Rust-based backdoor. The threat actor, UAT-11587, leverages legitimate Microsoft 365 services for C2.

₿

Encrygma is selling the entire Full Cyber Weapon Research of China-Nexus UAT-11587 Deploys 'Antino' Backdoor via Microsoft 365 Infrastructure for ₿ 0.10 BTC. Contact us.

04 October 2026Last updated 04 October 20264 min readCisco Talos
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
High
Actor Type:
Nation-State
Geography:
Asia
Confidence:
High Confidence
Source:
Cisco Talos
Read Time:
4 min

Executive Summary

In a sophisticated cyber espionage campaign identified in early October 2026, a China-nexus threat actor tracked as UAT-11587 has been observed targeting government and policy organizations across Asia and Syria. The campaign centers on the deployment of a previously undocumented, Rust-based Windows backdoor dubbed 'Antino'. By abusing legitimate Microsoft 365 services—specifically Outlook and OneDrive—for command-and-control (C2) operations, the actor has successfully maintained persistence while evading traditional network-based detection mechanisms.

Threat Analysis

UAT-11587 demonstrates a high level of operational security and strategic focus. The campaign, which gained momentum throughout September 2026, targets sensitive sectors including think tanks, civil society policy communities, and government ministries. The use of Rust for the Antino malware suggests a deliberate effort to complicate static analysis and increase the difficulty of signature-based detection. The actor's reliance on cloud-native infrastructure for C2 indicates a shift toward 'living-off-the-cloud' tactics, making it increasingly difficult for defenders to distinguish malicious traffic from legitimate enterprise activity.

Technical Details

The Antino backdoor is a modular, multi-stage implant written in Rust. Upon initial infection, typically delivered via highly targeted spear-phishing lures, the malware establishes a foothold on the victim's machine. The primary innovation in this campaign is the C2 architecture: Antino utilizes Microsoft Outlook and OneDrive APIs to exfiltrate data and receive tasking. By embedding commands within seemingly benign email drafts or hidden files stored in OneDrive, the actor bypasses standard firewall and proxy restrictions that would otherwise flag unauthorized outbound connections to unknown C2 servers.

Attribution Assessment

Based on TTPs, infrastructure overlap, and the geographic focus on Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, researchers have attributed this activity to a China-nexus threat actor. The group's methodology aligns with broader trends observed in recent years, where state-aligned actors increasingly utilize commercial cloud platforms to mask their espionage activities. The specific targeting of policy-making bodies suggests a strategic intelligence-gathering mission aimed at regional geopolitical influence.

Implications

The use of Microsoft 365 as a C2 channel poses a significant challenge for security operations centers (SOCs). Traditional perimeter defenses are ineffective against this vector, as the traffic originates from trusted, legitimate service providers. Organizations must shift their focus toward behavioral analytics and endpoint detection to identify the anomalous execution of the Antino backdoor rather than relying on network traffic filtering.

Recommendations

  1. Implement strict conditional access policies for Microsoft 365 environments to limit API access to known, authorized applications.
  2. Deploy advanced Endpoint Detection and Response (EDR) solutions capable of identifying suspicious process behaviors associated with Rust-based binaries.
  3. Conduct regular threat hunting exercises focusing on anomalous Outlook and OneDrive activity, such as unexpected file creation or unusual API calls from non-standard user agents.
  4. Enhance user awareness training regarding spear-phishing, specifically focusing on lures that mimic government or policy-related communications.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo