Cisco Talos has uncovered a sustained espionage campaign attributed with high confidence to a China-nexus threat actor tracked as UAT-11587, targeting government, defense, diplomatic, policy, research, and civil-society organizations across Asia. Talos first observed the activity in September 2025 and, by July 2026, had identified at least 10 confirmed and five probable affected institutional environments, one additional intended target, and roughly 350 compromised endpoints across eight countries. The affected or targeted countries include Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria.
The victim profile is important because this is not broad commodity malware distribution. Talos says the actor consistently focused on organizations connected to defense, national security, executive government, foreign affairs, law enforcement, border security, parliaments, government IT, universities, think tanks, human-rights groups, and public-policy institutions. Combined with carefully tailored political and diplomatic lures and the backdoor’s emphasis on persistent access and information collection, Talos assesses with moderate confidence that the campaign is primarily an intelligence-gathering operation.
India is particularly relevant in this campaign. Talos observed the largest concentrated wave of activity on June 8 and 9, 2026, when approximately 57 newly observed endpoints were associated with India. Indian-themed lure filenames included references such as “Items likely to be considered in the next Cabinet meeting” and “UO - C-DAC”, strongly suggesting targeting of Indian government, technology, research, or policy audiences. This indicates that the campaign was not merely regionally broad but also adapted its content to specific institutions and interests within each country.
The social-engineering component is particularly well designed. In one branch, UAT-11587 recreated Gmail’s native attachment preview interface directly inside the email body. The fake attachment card was built from inline images and wrapped in a link pointing to attacker-controlled infrastructure. To the recipient, the message could look almost indistinguishable from a normal Gmail attachment, but clicking the apparent document initiated the malware-delivery chain. Talos also observed tailored decoy documents involving Taiwan information warfare, legislative tax rules, Indo-Pacific security discussions, maritime policy, foreign affairs, bilateral summits, and human-rights themes.
The actor also abused a subtle weakness in email trust signals. Messages were sent through Migadu using an attacker-controlled envelope-sender domain while the visible From header displayed the identity of the organization being impersonated. SPF passed because the attacker’s actual sending infrastructure was authorized for its own domain, while DMARC correctly detected the mismatch. However, because the spoofed domain used a non-enforcing p=none DMARC policy, the message was still delivered.
That is a useful reminder that SPF passing does not mean the sender displayed to the user is authentic. SPF verifies whether a server is allowed to send for the envelope domain, not whether the visible From address matches the sender the user believes they are communicating with. DMARC alignment is what closes that gap, and a monitoring-only policy may identify spoofing without actually preventing delivery.
The malware-delivery chain itself is unusually layered. Talos observed a five-stage sequence beginning with an HTA or WSF stager, followed by cloud-hosted JavaScript, encrypted serialized .NET objects, in-memory deserialization, a .NET downloader, and finally DLL sideloading of the Antino backdoor. The campaign made extensive use of Cloudflare Pages, Cloudflare R2, Amazon CloudFront, Microsoft-signed binaries, and Microsoft 365, deliberately placing malicious activity inside infrastructure that is widely trusted and commonly allowed through enterprise networks.
The first stage often uses mshta.exe to execute an HTA file downloaded through Cloudflare Pages. The stager hides or resizes its window, sends an execution-tracking request, and loads additional JavaScript from Cloudflare R2 or Amazon CloudFront. Talos observed target-specific identifiers in the delivery URLs, suggesting the actor could track whether a particular recipient had actually executed the lure.
The second stage downloads several encrypted resources and decrypts them using custom Base64 processing and RC4. These include JavaScript orchestration code and serialized .NET gadget objects. Rather than simply dropping another executable, the malware uses BinaryFormatter deserialization and .NET gadget chains to load code directly inside mshta.exe.
That choice matters because it creates a more complex behavioral chain for defenders to recognize. The attacker is not relying on one obvious malware binary. Instead, trusted Windows scripting infrastructure, .NET runtime behavior, in-memory code loading, and cloud delivery services are combined to eventually reach the final backdoor.
The next stage downloads a legitimate Microsoft-signed executable called GatherOsState.exe, together with a malicious slc.dll. When the trusted Microsoft binary runs, it loads the attacker-controlled DLL from its local directory. This is classic DLL sideloading: the legitimate executable itself remains untouched, but its normal dependency-loading behavior is abused to execute malicious code.
That malicious DLL is Antino, a previously undocumented Rust-based Windows backdoor. Talos found both 32-bit and 64-bit variants and two distinct generations of the malware, suggesting active development rather than one static tool. Antino can perform host reconnaissance, run cmd.exe and PowerShell commands, enumerate files, execute additional programs, upload and download files, load arbitrary shellcode directly into memory, establish persistence through Registry Run keys, and terminate itself on command.
The most interesting technical feature, however, is Antino’s command-and-control architecture.
Antino does not rely on a traditional attacker-controlled C2 server.
Instead, it communicates entirely through Microsoft 365, using Microsoft Graph APIs to interact with Outlook and OneDrive. Outbound traffic therefore goes to legitimate Microsoft infrastructure such as graph.microsoft.com and login.microsoftonline.com, destinations that almost every enterprise already trusts.
This is a particularly effective form of dead-drop command and control.
Antino uses OneDrive for heartbeats, file transfer, and staging, while Outlook mailboxes are used to transmit commands and receive results. The implant periodically uploads JSON heartbeat files containing information such as the hostname, username, platform, online status, timestamp, session ID, and campaign identifier.
For command execution, Antino polls an attacker-controlled Outlook mailbox roughly every 10 seconds. Commands arrive as email messages whose subjects follow patterns such as command_req_[session_id], while responses use corresponding command_res_[session_id] messages. The body contains JSON describing the requested action and associated parameters.
This architecture has several advantages for the attacker.
There is no obvious malicious C2 domain to block.
The network connection is encrypted.
The destination belongs to Microsoft.
The same infrastructure is used by legitimate Office and cloud applications every day.
From a network-only perspective, the traffic may look like ordinary Microsoft 365 synchronization.
That places much greater importance on identity, endpoint, and application telemetry.
The Microsoft Graph authentication itself is also notable. Antino Gen2 uses the OAuth 2.0 client-credentials flow, allowing an attacker-controlled Entra ID application to communicate with Outlook and OneDrive without an interactive human login.
That means defenders cannot assume that every Graph API interaction maps neatly to a user clicking something in Microsoft 365.
Non-human identities and service principals have become part of the attack surface.
Security teams should monitor unusual Graph API clients, unexpected application registrations, suspicious OAuth permissions, and applications accessing Outlook or OneDrive from systems where such activity is not expected.
The use of trusted cloud services extends through nearly the entire campaign.
Cloudflare is used for delivery and execution tracking.
Amazon CloudFront provides additional payload distribution.
Microsoft-signed binaries provide DLL sideloading hosts.
Microsoft 365 becomes the C2 channel.
Each individual platform is legitimate.
The maliciousness appears in how those platforms are chained together.
This is increasingly characteristic of modern targeted intrusion activity. Attackers know that defenders heavily scrutinize unfamiliar domains, unsigned binaries, and obviously malicious infrastructure. So instead of building everything themselves, they borrow infrastructure defenders are reluctant to block.
The campaign demonstrates why domain reputation alone is becoming less useful.
graph.microsoft.com is trustworthy.
A connection to it is not automatically trustworthy.
Cloudflare is trustworthy.
A file hosted there is not automatically trustworthy.
A Microsoft-signed executable is trustworthy for its intended purpose.
It is not automatically trustworthy when executed from an unusual directory beside an attacker-controlled DLL.
Context matters more than brand.
Antino also supports direct in-memory shellcode execution, which allows operators to introduce additional tools without writing conventional executables to disk. Talos found a sleep-masking mechanism that can change the memory permissions of loaded payloads, encrypt their contents while sleeping, and then restore them later. This is intended to reduce the window during which memory scanners can detect the payload.
That capability makes Antino more than a simple remote shell.
It functions as an extensible espionage platform.
The backdoor provides persistence and communication.
The operator can then decide what additional tooling to deliver depending on the target.
That is particularly suitable for intelligence operations, where different victims may require different follow-on tools for credential theft, collection, lateral movement, or document exfiltration.
The attribution also deserves careful treatment.
Talos says it assesses with high confidence that UAT-11587 is China-nexus, but it does not attribute the cluster to a named Chinese government organization. The evidence includes Simplified Chinese metadata, UTC+8 preparation timestamps, repeated use of rsproxy.cn, targeting aligned with Chinese strategic interests, and some infrastructure overlap with previously reported China-nexus activity.
No single indicator proves attribution.
UTC+8 is used in several countries.
A Chinese Rust package mirror can be accessed from anywhere.
Cloud infrastructure can be reused.
Talos’ assessment is based on the combined pattern, not one smoking gun.
That distinction should remain explicit.
Talos also found overlap with activity Symantec tracks as Jewelbug, but the researchers did not independently verify whether UAT-11587 is the same actor or whether reported financially motivated Jewelbug activity is directly connected. Talos therefore continues tracking UAT-11587 separately.
From a defensive standpoint, the best opportunities appear early in the infection chain.
Organizations should monitor or restrict unnecessary execution of:
mshta.exe
Windows Script Host
HTA and WSF files
unexpected JScript execution
BinaryFormatter deserialization behavior
and signed binaries loading DLLs from user-writable or temporary directories.
mshta.exe deserves particular scrutiny in high-security government environments. Many modern organizations have little legitimate need for users to execute arbitrary HTA content downloaded from email or cloud-storage links.
Application-control policies can reduce this attack surface substantially.
Email security should also look beyond conventional attachment scanning.
The fake Gmail attachment card demonstrates how HTML content inside an email can visually impersonate the email client itself.
Security controls should inspect links embedded in styled attachment elements rather than trusting what the interface appears to show.
Users should be taught that an attachment preview is not necessarily a real attachment.
They should verify where the element actually links before opening highly sensitive policy or government documents.
Organizations should also enforce DMARC with p=quarantine or p=reject wherever operationally practical.
A monitoring-only p=none policy can tell an organization that somebody is impersonating its domain while politely allowing the impersonation to continue reaching victims, which is security theater with unusually good reporting.
The Antino C2 technique also argues for better Microsoft 365 monitoring.
Security teams should review:
unusual Microsoft Graph client activity,
unexpected Entra application identities,
abnormal Outlook mailbox API usage,
rapid periodic OneDrive writes,
non-Office processes communicating with Microsoft Graph,
and endpoints making Microsoft 365 API calls despite having no legitimate business reason to do so.
The fact that the destination is Microsoft should reduce false positives only after the process and identity context have been validated.
For Indian government, defense, research, and technology organizations, this campaign deserves particular attention because Talos directly observed India-focused activity and lures apparently referencing Cabinet discussions and C-DAC. The concentrated June wave associated with approximately 57 endpoints suggests India was not incidental collateral in a wider Asian campaign.
Organizations handling strategic research, policy development, defense technology, diplomatic affairs, maritime issues, border policy, or national-security subjects should therefore assume that professionally written policy documents and event invitations can be part of the attack surface.
The lure may contain entirely credible geopolitical material.
That is exactly what makes it useful.
The broader attack chain can be summarized as:
targeted spear-phishing → fake Gmail attachment interface or tailored policy lure → Cloudflare-hosted HTA/WSF → mshta.exe → encrypted JScript and .NET serialized gadgets → BinaryFormatter execution → in-memory .NET downloader → legitimate Microsoft GatherOsState.exe → DLL sideloading → Antino → Outlook and OneDrive dead-drop C2 → persistent intelligence collection
Every stage tries to reduce the number of obviously malicious elements.
Trusted cloud services host payloads.
Trusted Microsoft infrastructure handles command and control.
A trusted Microsoft binary starts the implant.
Legitimate policy documents distract the victim.
The malware therefore hides less by disappearing and more by surrounding itself with trusted infrastructure.
That may be the most important lesson from UAT-11587.
The campaign shows that defenders can no longer treat reputation as a binary security control.
A Microsoft connection can carry malware commands.
A Cloudflare URL can host a loader.
A signed Microsoft executable can load a malicious DLL.
A convincing Gmail attachment can be nothing more than attacker-generated HTML.
The question is no longer simply:
“Is this service trusted?”
It is:
“Is this particular use of the trusted service expected for this user, process, device, and organization?”
For targeted espionage campaigns, that contextual question increasingly determines whether defenders see the attack or merely see a collection of legitimate technologies behaving exactly as they were designed to.

Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.
Source: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor via Cisco Talos — published 30 Sep 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.