October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Antino routes commands through Outlook and stores heartbeats and transferred files in OneDrive. Here is how the UAT-11587 campaign works and what defenders should monitor.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Antino hides command-and-control (C2) in Microsoft 365: it uses Outlook mailbox messages to receive commands and return results, while OneDrive stores implant heartbeats and files moving between operators and compromised computers. Cisco Talos tracks the campaign as UAT-11587 and assesses with high confidence that it is China-nexus. The activity targets public-sector and policy organizations, so defenders should correlate Microsoft Graph and mailbox activity with endpoint process and DLL-loading telemetry rather than treating connections to Microsoft cloud services as inherently benign.

What UAT-11587 targeted

Cisco Talos observed UAT-11587 activity from September 2025 through July 2026. By July 2026, Talos reported at least 10 confirmed and five probable affected institutional environments, one additional intended target, and approximately 350 compromised endpoints. The environments were associated with Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. Talos also reported a wave on June 8–9, 2026, that added around 57 newly observed India-associated endpoints.

Targets spanned defense and national security, central government, diplomacy, justice and border security, legislatures, government IT, universities, think tanks, civil society, and policy organizations. Talos bases its high-confidence China-nexus assessment on the totality of technical and operational evidence, including Simplified Chinese metadata and author values, UTC+08:00 artifacts, the targeting pattern, and repeated use of the China-focused rsproxy.cn Rust mirror.

How Outlook and OneDrive divide the C2 work

Antino uses Microsoft Graph instead of relying on a dedicated attacker-operated C2 server. The implant connects to graph.microsoft.com and login.microsoftonline.com, familiar Microsoft service domains that may already be allowed in enterprise networks. In the documented design, OneDrive functions as a status and file-transfer store; Outlook carries tasking and responses.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Microsoft 365 component Antino’s use Documented artifact
OneDrive heartbeat storage Stores JSON reporting implant status and host details. /antino/heartbeats/{id}.json
OneDrive victim-to-operator transfer Holds files uploaded from compromised hosts for operator retrieval. /antino_downloads/{file}
OneDrive operator-to-victim transfer Holds tools staged by the operator for delivery to compromised hosts. /antino_uploads/{file}
Outlook mailbox Carries command requests and responses in message bodies. Subjects begin command_req_[session_id] or command_res_[session_id].

Heartbeat JSON includes a session ID, timestamp, online/offline status, machine name, username, platform, and campaign code. In Gen2, session IDs are random UUID v4 values and the implant resends a heartbeat every minute. The implant polls the operator’s mailbox approximately every 10 seconds. Command messages contain JSON fields named command_type, command_data, and request_id. Gen2 uses OAuth 2.0 client credentials; Talos does not establish in the available campaign details that every build uses the same authentication method.

How the infection chain reaches the implant

  1. Tailored lure: A spear-phishing message uses a decoy, including a fake Gmail attachment widget, to direct a victim to a Cloudflare Pages site.
  2. Cloud-hosted staging: The site serves an HTA or WSF stager, which downloads JavaScript from Cloudflare R2 or Amazon CloudFront.
  3. Script and .NET execution: The script uses custom Base64 handling and RC4 to decrypt resources, then abuses unsafe .NET BinaryFormatter deserialization and gadget chains to load a .NET assembly in mshta.exe.
  4. Downloader and sideloading: A downloader retrieves a decoy document and a DLL-sideloading bundle. Microsoft-signed GatherOsState.exe loads the adjacent slc.dll, which is the Antino implant.

Talos identified Cloudflare Pages hosting malicious HTA/WSF files and execution tracking, Cloudflare R2 storing encoded loaders, decoys, and payload components, and Amazon CloudFront delivering additional scripts and content. The report also names software-themed delivery domains including microsoft-flash[.]com and wps-cn[.]com. These indicators describe observed campaign infrastructure; they should be assessed alongside current threat intelligence and an organization’s own telemetry.

What Antino can do on a compromised Windows host

Antino is a Rust-compiled Windows backdoor. Talos documents handlers for the following operations, while noting that availability varies by build:

  • system_info for host reconnaissance.
  • cmd and powershell for command-shell and PowerShell execution.
  • execute_program to run an arbitrary program.
  • list_files, upload_file, and download_file for file discovery and transfer.
  • load_shellcode for in-memory shellcode loading.
  • add_to_run for persistence through a Registry Run value.
  • exit to terminate the implant.

The exact set available in an incident depends on the deployed build; the handler list should not be read as proof that every infected endpoint received every capability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What defenders should monitor in Microsoft 365 and on endpoints

Because the C2 blends into legitimate cloud services, a domain allowlist or a single Microsoft 365 alert is not enough to establish whether activity is benign. Correlate identity, Graph, mailbox, OneDrive, and endpoint events around the same user, host, application, and time window. The following priorities are derived from the documented behavior and need validation against each organization’s normal use.

  • OAuth application activity: Review unusual client-credential applications and their Graph activity. Check application identity, registration and consent context, sign-in activity, and which mail or OneDrive resources it accessed. The campaign details establish use of client credentials for Gen2, but do not specify a universal permission set to use as a signature.
  • Graph access to mail and OneDrive: Look for unexpected application access that spans mailbox and OneDrive data, particularly when associated with a host showing suspicious script or DLL activity. Compare the application and access pattern with approved automation.
  • Mailbox subjects and polling pattern: Search for repeated messages with subjects beginning command_req_ or command_res_, and investigate recurring access patterns consistent with frequent mailbox polling. Review surrounding message and application context rather than relying on subject text alone.
  • OneDrive paths and file movement: Hunt for creation or access of /antino/heartbeats/, /antino_downloads/, and /antino_uploads/, then correlate file activity with the application and endpoint involved. Unusual path names are useful leads, not proof by themselves.
  • Endpoint execution chain: Investigate mshta.exe or wscript.exe launching or retrieving cloud-hosted stages, suspicious .NET BinaryFormatter activity, and Microsoft-signed GatherOsState.exe loading an adjacent slc.dll. Verify the executable’s signature and examine its parent process, command line, file origin, and loaded modules; a valid signature does not make unexpected DLL loading safe.

Preserve relevant Entra ID, Microsoft Graph, Exchange/Outlook, OneDrive, and endpoint records together so investigators can connect an application’s cloud activity to the process that initiated it. Where suspicious access is confirmed, follow the organization’s incident-response process to contain the affected identity or application and host, preserve evidence, and assess whether files or credentials were exposed. Avoid blocking broad Microsoft service domains solely because this campaign used them: that can disrupt legitimate work without distinguishing the malicious application or process.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known—and not known—about Jewelbug

Talos found overlap between UAT-11587 and Symantec’s Jewelbug activity set, but could not independently verify a connection between this espionage campaign and Jewelbug’s financially motivated cryptocurrency activity. Talos therefore tracks UAT-11587 separately. The overlap is not evidence that the two activities share an operator or objective.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.