A newly documented espionage campaign has targeted government, policy, and academic organizations across Asia and the Middle East, deploying a sophisticated Rust-compiled implant known as the Antino backdoor. According to Cisco Talos, the intrusion cluster is tracked under the identifier UAT-11587 and has impacted at least 16 entities across eight countries since September 2025. The adversary demonstrates significant regional targeting preferences, focusing on legislative, maritime, diplomatic, and civil defense sectors aligned with strategic interests in Beijing.
Technical Analysis of the Antino Backdoor
The attack chain begins with carefully tailored spear-phishing messages designed to bypass standard perimeter security controls. To maximize success rates against targets, UAT-11587 utilizes sender spoofing to circumvent SPF and DMARC checks. Furthermore, operators replicate Gmail’s native attachment preview widget inside the email HTML body using Base64-encoded MIME parts and inline PNG images. This fake attachment widget links to an external Cloudflare Pages URL that serves an initial HTA or WSF stager.
Once the stager executes on the host, it triggers a multi-stage infection process:
- Staging and Decryption: A JavaScript downloader fetches and decrypts subsequent payloads, initiating a .NET deserialization chain.
- Launcher Execution: The chain loads a custom .NET downloader and launcher designated as
TestAssembly.dll. - DLL Sideloading: The final implant (
slc.dll) is loaded via DLL sideloading using a legitimate Microsoft-signed binary, specificallyGatherOsState.exe.
Living-off-Trusted-Cloud Command and Control
Unlike traditional malware families that rely on dedicated external infrastructure, the Antino backdoor blends malicious traffic with legitimate cloud services. As detailed in the initial The Hacker News report, the malware leverages Microsoft Graph to interact exclusively with Microsoft 365 applications for its command-and-control (C2) infrastructure.
Antino uses Outlook mailboxes and OneDrive cloud storage as dead drops. The backdoor checks an attacker-controlled Outlook folder every 10 seconds for messages bearing the subject prefix command_req_[session_id] to retrieve incoming instructions. For operational heartbeats and file transfers, the malware switches to OneDrive objects. Capabilities of the implant include host reconnaissance, process enumeration, directory listing, PowerShell script execution, and in-memory shellcode loading via the Windows Scripted Diagnostics framework.
Actionable Mitigations and Detection Strategies
Detecting living-off-the-land binaries and abused cloud services requires focused telemetry tuning rather than relying strictly on signature-based defenses. Security teams should implement the following hardening and monitoring steps:
- Monitor DLL Sideloading: Audit execution telemetry for native Microsoft binaries such as
GatherOsState.exeloading non-standard dynamic-link libraries from working directories. - Inspect M365 API Usage: Audit Microsoft Graph API activity and Azure AD logs for anomalous mailbox access patterns, recurring programmatic email queries with specific subject prefixes, and unusual OneDrive file synchronization behaviors.
- Endpoint Behavioral Rules: Deploy strict endpoint detection rules to flag the execution of HTA and WSF stagers spawning obfuscated JavaScript or executing PowerShell via native diagnostic components.
Related: UAT-11587 Deploys Antino Backdoor Against Asian Governments, HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2