Researchers at Cisco Talos have uncovered an espionage campaign, tracked as UAT-11587, that targets government and policy organizations across Asia. The campaign deploys a previously undocumented Windows backdoor named Antino, a Rust-compiled implant that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading, and persistence. Targets include Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and, since around May 2026, Syria.
Antino's native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive as dead drops rather than relying on a conspicuous dedicated C2 server. For initial access, the actor uses spear-phishing emails with spoofed sender identities to bypass SPF and DMARC checks, and a closely replicated Gmail attachment preview widget inside the email HTML that points to an attacker-controlled Cloudflare Pages URL.
Talos assesses the adversary as China-nexus with high confidence, citing Simplified Chinese metadata, a UTC+08:00 time zone, Cargo registry paths referencing rsproxy.cn, and a CloudFront domain previously linked to UNC6384. While UAT-11587 shares some overlap with Jewelbug, Talos says its investigation found no connection to Jewelbug's financially motivated activity, so it designates UAT-11587 as a separate activity set. The attack chain begins with an HTA or WSF stager, proceeds through a JavaScript downloader and a .NET deserialization chain, and ends with DLL sideloading of the Antino backdoor via a legitimate Microsoft-signed binary.