Antino hides command-and-control (C2) in Microsoft 365: it uses Outlook mailbox messages to receive commands and return results, while OneDrive stores implant heartbeats and files moving between operators and compromised computers. Cisco Talos tracks the campaign as UAT-11587 and assesses with high confidence that it is China-nexus. The activity targets public-sector and policy organizations, so defenders should correlate Microsoft Graph and mailbox activity with endpoint process and DLL-loading telemetry rather than treating connections to Microsoft cloud services as inherently benign.
What UAT-11587 targeted
Cisco Talos observed UAT-11587 activity from September 2025 through July 2026. By July 2026, Talos reported at least 10 confirmed and five probable affected institutional environments, one additional intended target, and approximately 350 compromised endpoints. The environments were associated with Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. Talos also reported a wave on June 8–9, 2026, that added around 57 newly observed India-associated endpoints.
Targets spanned defense and national security, central government, diplomacy, justice and border security, legislatures, government IT, universities, think tanks, civil society, and policy organizations. Talos bases its high-confidence China-nexus assessment on the totality of technical and operational evidence, including Simplified Chinese metadata and author values, UTC+08:00 artifacts, the targeting pattern, and repeated use of the China-focused rsproxy.cn Rust mirror.
How Outlook and OneDrive divide the C2 work
Antino uses Microsoft Graph instead of relying on a dedicated attacker-operated C2 server. The implant connects to graph.microsoft.com and login.microsoftonline.com, familiar Microsoft service domains that may already be allowed in enterprise networks. In the documented design, OneDrive functions as a status and file-transfer store; Outlook carries tasking and responses.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
| Microsoft 365 component | Antino’s use | Documented artifact |
|---|---|---|
| OneDrive heartbeat storage | Stores JSON reporting implant status and host details. | /antino/heartbeats/{id}.json |
| OneDrive victim-to-operator transfer | Holds files uploaded from compromised hosts for operator retrieval. | /antino_downloads/{file} |
| OneDrive operator-to-victim transfer | Holds tools staged by the operator for delivery to compromised hosts. | /antino_uploads/{file} |
| Outlook mailbox | Carries command requests and responses in message bodies. | Subjects begin command_req_[session_id] or command_res_[session_id]. |
Heartbeat JSON includes a session ID, timestamp, online/offline status, machine name, username, platform, and campaign code. In Gen2, session IDs are random UUID v4 values and the implant resends a heartbeat every minute. The implant polls the operator’s mailbox approximately every 10 seconds. Command messages contain JSON fields named command_type, command_data, and request_id. Gen2 uses OAuth 2.0 client credentials; Talos does not establish in the available campaign details that every build uses the same authentication method.
How the infection chain reaches the implant
- Tailored lure: A spear-phishing message uses a decoy, including a fake Gmail attachment widget, to direct a victim to a Cloudflare Pages site.
- Cloud-hosted staging: The site serves an HTA or WSF stager, which downloads JavaScript from Cloudflare R2 or Amazon CloudFront.
- Script and .NET execution: The script uses custom Base64 handling and RC4 to decrypt resources, then abuses unsafe .NET
BinaryFormatterdeserialization and gadget chains to load a .NET assembly inmshta.exe. - Downloader and sideloading: A downloader retrieves a decoy document and a DLL-sideloading bundle. Microsoft-signed
GatherOsState.exeloads the adjacentslc.dll, which is the Antino implant.
Talos identified Cloudflare Pages hosting malicious HTA/WSF files and execution tracking, Cloudflare R2 storing encoded loaders, decoys, and payload components, and Amazon CloudFront delivering additional scripts and content. The report also names software-themed delivery domains including microsoft-flash[.]com and wps-cn[.]com. These indicators describe observed campaign infrastructure; they should be assessed alongside current threat intelligence and an organization’s own telemetry.
What Antino can do on a compromised Windows host
Antino is a Rust-compiled Windows backdoor. Talos documents handlers for the following operations, while noting that availability varies by build:
system_infofor host reconnaissance.cmdandpowershellfor command-shell and PowerShell execution.execute_programto run an arbitrary program.list_files,upload_file, anddownload_filefor file discovery and transfer.load_shellcodefor in-memory shellcode loading.add_to_runfor persistence through a Registry Run value.exitto terminate the implant.
The exact set available in an incident depends on the deployed build; the handler list should not be read as proof that every infected endpoint received every capability.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWhat defenders should monitor in Microsoft 365 and on endpoints
Because the C2 blends into legitimate cloud services, a domain allowlist or a single Microsoft 365 alert is not enough to establish whether activity is benign. Correlate identity, Graph, mailbox, OneDrive, and endpoint events around the same user, host, application, and time window. The following priorities are derived from the documented behavior and need validation against each organization’s normal use.
- OAuth application activity: Review unusual client-credential applications and their Graph activity. Check application identity, registration and consent context, sign-in activity, and which mail or OneDrive resources it accessed. The campaign details establish use of client credentials for Gen2, but do not specify a universal permission set to use as a signature.
- Graph access to mail and OneDrive: Look for unexpected application access that spans mailbox and OneDrive data, particularly when associated with a host showing suspicious script or DLL activity. Compare the application and access pattern with approved automation.
- Mailbox subjects and polling pattern: Search for repeated messages with subjects beginning
command_req_orcommand_res_, and investigate recurring access patterns consistent with frequent mailbox polling. Review surrounding message and application context rather than relying on subject text alone. - OneDrive paths and file movement: Hunt for creation or access of
/antino/heartbeats/,/antino_downloads/, and/antino_uploads/, then correlate file activity with the application and endpoint involved. Unusual path names are useful leads, not proof by themselves. - Endpoint execution chain: Investigate
mshta.exeorwscript.exelaunching or retrieving cloud-hosted stages, suspicious .NETBinaryFormatteractivity, and Microsoft-signedGatherOsState.exeloading an adjacentslc.dll. Verify the executable’s signature and examine its parent process, command line, file origin, and loaded modules; a valid signature does not make unexpected DLL loading safe.
Preserve relevant Entra ID, Microsoft Graph, Exchange/Outlook, OneDrive, and endpoint records together so investigators can connect an application’s cloud activity to the process that initiated it. Where suspicious access is confirmed, follow the organization’s incident-response process to contain the affected identity or application and host, preserve evidence, and assess whether files or credentials were exposed. Avoid blocking broad Microsoft service domains solely because this campaign used them: that can disrupt legitimate work without distinguishing the malicious application or process.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What is known—and not known—about Jewelbug
Talos found overlap between UAT-11587 and Symantec’s Jewelbug activity set, but could not independently verify a connection between this espionage campaign and Jewelbug’s financially motivated cryptocurrency activity. Talos therefore tracks UAT-11587 separately. The overlap is not evidence that the two activities share an operator or objective.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.




