Antino Hides Espionage Traffic Inside Outlook and OneDrive

UAT-11587 used Antino backdoor to target Asian government agencies, hiding C2 in Outlook and OneDrive via Microsoft Graph.

Antino Hides Espionage Traffic Inside Outlook and OneDrive
APT

Illustrative image generated with AI

Listen to this articleAudio edition · 9 min

UAT-11587 targeted public-sector organizations across Asia

Cisco Talos has tracked an espionage cluster designated UAT-11587 since September 2025. By July 2026, the activity had reached at least 16 government and policy organizations across eight Asian countries, according to reporting published on October 3, 2026.

The operation deployed Antino, a previously undocumented Windows backdoor that communicates through Microsoft 365 services. Instead of depending on a dedicated command-and-control server for its native channel, the malware uses Microsoft Graph to work with Outlook and OneDrive.

The reported targets included defense ministries, legislatures, foreign affairs offices, border and interior security agencies, think tanks, and civil society organizations. Such entities are likely to possess government, diplomatic, security, or policy information relevant to an intelligence operation.

Talos separately reported around 350 compromised endpoints across eight countries. That figure should not be treated as the number of targeted organizations. The largest short-term rise described in the reporting involved approximately 57 new endpoints in India over two days in June; the year for that June interval was not specified.

Outlook becomes the tasking channel

Antino is compiled in Rust and supports both 32-bit and 64-bit Windows. It can survey an infected host, invoke command shells or PowerShell, move files, execute shellcode directly from memory, and establish persistence.

Once active, the implant polls a folder in an Outlook mailbox every 10 seconds. Operator instructions and implant responses are represented as JSON inside specially constructed email subjects. Two prefixes distinguish the message types:

  • command_req_[session_id] identifies tasking sent to the implant.
  • command_res_[session_id] identifies results returned by the implant.

This design turns the mailbox into a control interface. Outlook carries commands and execution results, while Microsoft Graph provides the means to access the service programmatically.

OneDrive performs a different role. The operators use separate folders to move collected material and deliver additional tools or files. The terminology is presented from their viewpoint: “uploads” travel toward the victim, whereas “downloads” are retrieved from the compromised system.

Routing these exchanges through Microsoft 365 can make them resemble legitimate cloud activity. The reported behavior does not involve exploiting a Microsoft product vulnerability, and the account does not identify a dedicated external server for Antino’s native C2 mechanism.

Phishing combined tailored documents with visual impersonation

The initial delivery relied on targeted phishing. One lure masqueraded as workshop material concerning Taiwan’s information warfare. Another closely reproduced a genuine Taiwan Ministry of Finance ruling about the tax treatment of legislators, giving the document subject matter appropriate for public-sector recipients.

In another case, the operators repurposed an Associated Press report about alleged Russian offers to the United States concerning Venezuela. Related malware samples appeared on VirusTotal two days after the original story was published. The story’s publication date was not provided.

The campaign also exploited weaknesses in email authentication policy without bypassing the underlying protocols. Messages passed through a legitimate provider and used an authorized technical sending domain. Consequently, SPF validation succeeded for the actual sender.

However, the visible From address impersonated the targeted organization. That misalignment caused DMARC to fail. Delivery still occurred because the impersonated domain had configured its DMARC policy for monitoring rather than rejection.

A separate deception imitated Gmail’s attachment-preview interface. Embedded images and rendered HTML created a counterfeit preview card that directed recipients to an attacker-controlled page. This was an interface-copying technique, not exploitation of a Gmail software flaw.

Five execution stages ended in DLL sideloading

After a recipient followed the malicious link, the reported infection path proceeded through five stages. The available account does not enumerate each stage, but it identifies HTA files, Windows Script Host, and scripted .NET deserialization among the components.

During that sequence, the .NET technique repurposed an established gadget chain so attacker-controlled code would execute within a trusted process. The final stage used a signed Microsoft diagnostic binary to sideload Antino. Windows trusts that binary by default, giving the deployment chain a legitimate-looking execution component.

Cloudflare Pages, Cloudflare R2, and Amazon CloudFront reportedly transported almost every stage. Using widely deployed cloud infrastructure allowed the associated connections to appear alongside ordinary HTTPS traffic.

These details describe the observed delivery chain. They do not establish that every intrusion attributed to UAT-11587 followed exactly the same sequence.

Attribution rests on a collection of development clues

Talos assesses with high confidence that UAT-11587 has a China nexus. The conclusion is an analytic assessment based on multiple indicators, rather than a single artifact that conclusively identifies the operators.

Metadata from decoy documents included Simplified Chinese language tags and a UTC+8 timestamp. Talos also identified references in 10 Antino builds to a Rust package mirror designed to accelerate dependency downloads within mainland China.

The assessment additionally considers development, preparation-environment, targeting, and operational indicators. Together, these elements supported Talos’s confidence judgment.

They do not independently reveal the identities of the individuals operating UAT-11587. The China-nexus conclusion therefore remains an attributed intelligence assessment, not independently established identification of a particular organization or government unit.

Defenders can focus on protocol markers and cloud-service context

Antino’s functionality could support sustained surveillance, remote command execution, persistence, and the acquisition or delivery of files. Its use of familiar Microsoft 365 services presents the central defensive problem: the destination alone may look routine.

The prefixes command_req_[session_id] and command_res_[session_id] are concrete protocol markers that defenders may use as investigative leads. Their presence in Outlook data could warrant correlation with unusual mailbox access, Microsoft Graph activity, endpoint execution, and OneDrive transfers. The reporting does not establish how reliably those strings can be surfaced in every environment.

Email teams can also examine cases where SPF succeeds but DMARC fails because the visible sender does not align with the authenticated domain. In this campaign, a monitoring-only policy allowed spoofed messages to reach recipients despite that failure. Reviewing the policy and its operational consequences is therefore directly relevant to the documented delivery method.

The cited reporting does not specify patches, validated containment instructions, detection rules, file hashes, IP addresses, domains, or other conventional infrastructure indicators. That limitation applies to the material described here and does not demonstrate that Talos, Microsoft, or other vendors have not published additional resources elsewhere.

No formal severity score was provided. This is also not a CVE-based software flaw with a vendor patch path; the reported threat combines phishing, trusted cloud platforms, staged execution, and abuse of legitimate Microsoft 365 functionality.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →