China's UAT-11587 Targets Asian Governments via Antino Backdoor

•By CyberNewsAI Admin•VERIFIED INTEL
Threat intelligence dashboard visual analyzing China-nexus UAT-11587's Antino backdoor deployment across Asian government and policy institutions

SOC Briefing Summary :: Executive Key Takeaways

  • [01]China-nexus threat cluster UAT-11587 compromised 350+ endpoints across 16+ government and policy institutions in 8 Asian countries using the custom Antino Rust backdoor.
  • [02]Attackers cloned Gmail attachment preview widgets and exploited .NET BinaryFormatter deserialization to load payloads via signed Windows ADK DLL sideloading.
  • [03]Immediate action: Audit Entra ID OAuth application permissions for unauthorized Mail/Files Graph API scopes and block executable sideloading of GatherOsState.exe.
SHARE INTEL:Reddit

Executive Summary

Cisco Talos has uncovered a persistent, highly targeted cyber espionage campaign attributed with high confidence to the China-nexus threat cluster UAT-11587. Operating continuously from at least September 2025 through July 2026, the threat actors penetrated more than 16 confirmed or probable public-sector and national security-adjacent institutional environments across eight Asian nations—including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. Telemetry corroborates approximately 350 compromised endpoints across targeted foreign affairs ministries, defense establishments, parliamentary bodies, and civil society think tanks.

The intrusion lifecycle centers on the deployment of Antino, a previously undocumented, high-capability Windows backdoor compiled in Rust. Rather than maintaining dedicated command-and-control (C2) servers that trigger perimeter alerts, Antino communicates natively and exclusively through Microsoft 365. By abusing the Microsoft Graph API via OAuth 2.0 client-credentials authentication, the implant interacts with threat actor-controlled Outlook mailboxes and OneDrive folders as dead drops, polling for operator commands every 10 seconds and synchronizing exfiltrated data every minute.

UAT-11587's delivery mechanics exhibit remarkable tradecraft. The threat actors abused SMTP sender domain misalignment to bypass non-enforcing DMARC policies and cloned the exact HTML preview card of Google Gmail's native attachment widget. The resulting multi-stage chain weaponized in-memory .NET BinaryFormatter deserialization gadget chains and DLL sideloading through Microsoft's signed Windows Assessment and Deployment Kit (ADK) binary GatherOsState.exe.

Technical Vulnerability Analysis & Attack Chain

Attack Chain Flow
// Attack Chain Flow

Stage 1: Sender Spoofing & Gmail Widget Cloning

  • Sender Domain Misalignment: UAT-11587 routed spear-phishing emails through Migadu infrastructure, designating the attacker-controlled osc-cdn[.]com domain as the RFC5321 envelope sender. While this allowed messages to pass SPF authentication cleanly, the RFC5322 visible From header displayed the trusted identity of target organizations. Because target organizations maintained non-enforcing DMARC monitoring policies (p=none), recipient gateways accepted and delivered the spoofed messages despite DMARC validation failure.
  • HTML Attachment Card Emulation: In attacks targeting Gmail users, the operators embedded four Base64-encoded PNG images directly into the email HTML body, perfectly replicating Gmail's native attachment card interface. Clicking the preview redirected victims to protocol-relative Cloudflare Pages URLs formatted as //my-<project>.pages.dev/File_download?m=<target-id>, allowing attackers to log execution per victim.
  • Geopolitical & Policy Decoys: Decoys were rigorously customized to target institutions. Samples included Taiwan Ministry of Finance legislative tax rulings (GL005442), Taiwan information warfare studies referencing TikTok, CSIS Indo-Pacific Forecast 2026 event schedules targeting Indian policy circles, and Philippine maritime dispute resolutions concerning Bajo de Masinloc (Scarborough Shoal).

Stage 2: Cloudflare Stager & HTA Ingress

  • Living-off-the-Land Ingress: The Cloudflare Pages URL initiated the download of an HTML Application (.HTA) or Windows Script File (.WSF), executed via native Windows utilities mshta.exe or wscript.exe.
  • Execution Telemetry Beacon: Upon launch, the stager resized and hid its window, transmitting an HTTP GET request containing the lure title in the URI path to a fixed Cloudflare Pages telemetry hostname (oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev) to track successful victim detonations.
  • Encrypted Payload Retrieval: The stager pulled three encrypted staging assets from Cloudflare R2 (pub-<hex>.r2[.]dev) or Amazon CloudFront (d2nq35tel3ucuo[.]cloudfront[.]net): an encrypted JScript orchestrator (.js) and two encrypted .NET serialized gadget files (.txt). The stager applied custom Base64 decoding and decrypted each asset using RC4 with embedded keys.

Stage 3: .NET BinaryFormatter In-Memory Deserialization Chain

  • Scripted Gadget Chain Execution: The decrypted JScript instantiated COM-visible .NET 4.x runtime classes directly within mshta.exe and passed attacker-controlled streams into BinaryFormatter.Deserialize.
  • Two-Stage Deserialization Bypass:
    • Stage 1: Deserializes an assembly designed to bypass .NET Framework security mitigations introduced to restrict ActivitySurrogateSelector gadget chains. The code executed in a try/catch block to handle discrepancies across patch levels.
    • Stage 2: Leveraged the System.Windows.Forms.AxHost+State gadget coupled with ActivitySurrogateSelector to load an embedded PE file—TestAssembly.dll (GUID b2b3adb0-1669-4b94-86cb-6dd682ddbea3)—directly into mshta.exe process memory without writing bytes to disk.

Stage 4: Signed Host ADK DLL Sideloading

  • Staging Package Retrieval: TestAssembly.dll acted as an in-memory launcher, downloading a decoy document and a three-file bundle disguised with arbitrary extensions (.luy, .pzs, .syk) from Cloudflare R2.
  • ADK Binary Abuse: The downloader wrote the bundle to a user-writable directory (%LOCALAPPDATA%\Windows GatherOSStateKit\) and launched GatherOsState.exe, a legitimate Microsoft-signed Windows Assessment and Deployment Kit (ADK) binary.
  • DLL Hijacking: GatherOsState.exe automatically sideloaded slc.dll from its current working directory, calling the exported function SLOpen to transfer execution to the Antino backdoor runtime.

Stage 5: Antino Rust Backdoor Architecture & M365 C2

  • Compilation & Heritage: Antino is an advanced Windows backdoor authored in Rust, identified across 32-bit and 64-bit builds. PDB paths reveal development inside GitHub Actions Windows runners (D:\a\antino\antino\target\...) and dependency downloads sourced from Chinese Rust mirror rsproxy.cn.
  • Microsoft 365 Graph Dead-Drop C2: Antino does not maintain outbound connections to proprietary IP addresses. Instead, it authenticates to Microsoft Graph (graph.microsoft.com) and Microsoft Online (login.microsoftonline.com) using OAuth 2.0 client credentials:
    • Outlook Command Channel: Every 10 seconds, Antino queries the attacker's Outlook inbox for messages with subject command_req_[session_id]. It parses JSON tasking (cmd, powershell, load_shellcode, system_info), executes the directive, and replies with command_res_[session_id].
    • OneDrive File & Heartbeat Channel: Every 60 seconds, Antino uploads host telemetry to /antino/heartbeats/{session_id}.json. Operator-supplied tools are pulled from /antino_uploads/, and stolen files are pushed to /antino_downloads/.
  • In-Memory Sleep Masking (VEH): Antino hooks Sleep and VirtualAlloc and registers a Vectored Exception Handler (VEH). Before sleeping, the payload memory page is modified to PAGE_READWRITE and encrypted in place. Upon wake, execution triggers an access violation caught by the VEH, which restores execution permissions and decrypts memory, defeating automated in-memory scanners.
  • Scripted Diagnostics Proxying: Antino executes commands and establishes persistence by activating COM class CScriptedDiag ({1F3D8AA5-9EBF-4EE4-85C2-EA40379AEDE8}). It loads the native Windows Program Compatibility Wizard (PCW) package and directs sdiagnhost.exe -Embedding to execute malicious PowerShell scripts (result.ps1), writing HKCU Run keys through Microsoft-signed diagnostic infrastructure.

MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)

MITRE ATT&CK • OPERATIONAL TTP MAPPING
TacticTechnique IDTechnique NameOperational Context
Resource DevelopmentT1583.001Acquire Infrastructure: DomainsRegistering spoof domains (osc-cdn[.]com, microsoft-flash[.]com, wps-cn[.]com)
Initial AccessT1566.002Phishing: Spearphishing LinkReconstructing Gmail attachment cards in HTML leading to Cloudflare Pages URLs
ExecutionT1059.007Command and Scripting Interpreter: JavaScriptIn-memory JScript decrypting and orchestrating .NET gadget deserialization
ExecutionT1203Exploitation for Client ExecutionBinaryFormatter AxHost+State and ActivitySurrogateSelector deserialization
Defense EvasionT1574.002Hijack Execution Flow: DLL Side-LoadingMicrosoft ADK binary GatherOsState.exe sideloading malicious slc.dll
Defense EvasionT1027Obfuscated Files or InformationIn-memory sleep masking with PAGE_READWRITE encryption and VEH dispatching
Defense EvasionT1218System Binary Proxy ExecutionProxying PowerShell via Windows Scripted Diagnostics Host (sdiagnhost.exe)
PersistenceT1547.001Boot or Logon Autostart: Registry Run KeysAdding HKCU Run keys via sdiagnhost.exe executing temporary result.ps1 scripts
Command and ControlT1102.002Web Service: Bidirectional CommunicationMicrosoft Graph API dead-drop communications via Outlook emails and OneDrive folders
ExfiltrationT1567.002Exfiltration Over Web Service: Cloud StorageExfiltrating sensitive host files to OneDrive /antino_downloads/ directory

Threat Actor Profile & Campaign Attribution

Threat Cluster: UAT-11587 (China-Nexus Advanced Persistent Threat).

Attribution Assessment & Intelligence Markers:

  • Confidence Level: High confidence China-nexus attribution based on the convergence of technical, linguistic, operational, and infrastructural artifacts.
  • Preparation Environment Telemetry: Decoy document metadata recovered from Taiwan operations revealed internal document creation timestamps synchronized to UTC+8, the zh-CN language identifier, and the Simplified Chinese author string 未定义 ("undefined"). While UTC+8 spans several jurisdictions, pairing Simplified Chinese tags with +08:00 strongly indicates a mainland Chinese developer workstation targeting Traditional Chinese-speaking institutions.
  • Rust Build Ecosystem: Ten distinct Antino compiler builds recovered across campaigns contained embedded Cargo registry paths explicitly referencing `rsproxy.cn`, a mainland Chinese Rust package mirror utilized to accelerate crate dependencies behind national network boundaries.
  • Overlaps with Known Threat Clusters: Symantec recently tracked overlapping Antino activity under the moniker Jewelbug, noting infrastructure intersections between cyber espionage and cryptocurrency fraud. Additionally, UAT-11587 leveraged Amazon CloudFront distribution d32tpl7xt7175h[.]cloudfront[.]net, previously attributed by Arctic Wolf to Chinese state-sponsored threat group UNC6384 (distributors of PlugX).

Detection & SOC Mitigation Playbook

1. Patch & Workaround Guidance

  • Restrict Windows Scripted Diagnostics Engine: Implement Application Control (AppLocker or Windows Defender Application Control [WDAC]) to restrict execution of sdiagnhost.exe and block script execution from C:\Windows\Temp\SDIAG_* directories.
  • Audit Microsoft Entra ID Application Permissions: Review all registered Entra ID multi-tenant and single-tenant applications for high-privilege Microsoft Graph API permissions granted under the OAuth 2.0 client-credentials flow, specifically Mail.ReadWrite, Mail.Send, Files.ReadWrite, and Files.ReadWrite.All.
  • Block ADK Sideloading Paths: Restrict GatherOsState.exe from executing outside its default installation path (C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\).

2. Network & Perimeter Defenses

  • Enforce Strict DMARC Policy (`p=reject`): Upgrade organizational DMARC records from passive monitoring (p=none) to strict enforcement (p=reject or p=quarantine) to prevent attackers from abusing envelope-versus-header misalignment through external mail relays (e.g., Migadu).
  • Inspect Cloudflare Pages & R2 Outbound Connections: Inspect proxy logs for anomalous HTTPS requests to *.pages.dev and *.r2.dev containing query strings with tracking parameters (e.g., ?m= or ?track).
  • Deploy Snort / ClamAV Rules: Ensure intrusion prevention systems are updated with Snort rules 1:66880, 1:66881, and 1:66882 covering Antino staging traffic.

3. Endpoint Detection & Hunting Query

QUERY / DETECTION_RULE
SIGMA / YAML
title: UAT-11587 GatherOsState Sideloading and Scripted Diagnostics Abuse
id: 7c3d2e1f-4b5a-49e8-a6d1-9f0e8b2a3c4d
status: experimental
description: Detects GatherOsState.exe executing outside Windows Kits directory or sdiagnhost.exe executing PowerShell scripts from Temp directories indicative of Antino backdoor persistence
references:
  - https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/
  - https://cybernewsai.com/blog/china-uat-11587-antino-backdoor-espionage
author: CyberNewsAI Threat Intelligence
date: 2026/09/30
logsource:
  category: process_creation
  product: windows
detection:
  selection_sideload:
    Image|endswith: '\GatherOsState.exe'
  filter_legit_adk:
    Image|startswith: 'C:\Program Files (x86)\Windows Kits\'
  selection_diagnostics:
    ParentImage|endswith: '\sdiagnhost.exe'
    Image|endswith: '\powershell.exe'
    CommandLine|contains:
      - '\Temp\SDIAG_'
      - 'result.ps1'
  selection_registry_run:
    CommandLine|contains:
      - 'Windows GatherOSStateKit'
      - 'Antino'
  condition: (selection_sideload and not filter_legit_adk) or selection_diagnostics or selection_registry_run
level: high
tags:
  - attack.defense_evasion
  - attack.t1574.002
  - attack.t1218
  - attack.persistence
  - attack.t1547.001
falsepositives:
  - Legitimate Windows Assessment and Deployment Kit testing by IT engineers in non-standard paths
QUERY / DETECTION_RULE
SENTINEL / KQL
// Microsoft Sentinel / Defender XDR - Hunting for UAT-11587 Antino Infection Artifacts
// Identifies GatherOsState DLL sideloading, sdiagnhost proxying, and M365 staging directories
let SideloadEvents = DeviceProcessEvents
| where Timestamp >= ago(30d)
| where FileName =~ "GatherOsState.exe" and not(FolderPath startswith @"C:\Program Files (x86)\Windows Kits\")
| project Timestamp, DeviceName, ActionType="Abnormal GatherOsState Execution", FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, AccountName;
let DiagnosticAbuse = DeviceProcessEvents
| where Timestamp >= ago(30d)
| where InitiatingProcessFileName =~ "sdiagnhost.exe" and FileName =~ "powershell.exe"
| where ProcessCommandLine has_any ("SDIAG_", "result.ps1")
| project Timestamp, DeviceName, ActionType="Scripted Diagnostics PowerShell Proxy", FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, AccountName;
let StagingFiles = DeviceFileEvents
| where Timestamp >= ago(30d)
| where FolderPath has @"Windows GatherOSStateKit" or FileName in~ ("slc.dll", "OsGather.dat")
| project Timestamp, DeviceName, ActionType="Antino Staging File Event", FileName, FolderPath, ProcessCommandLine="", InitiatingProcessFileName, AccountName="";
union SideloadEvents, DiagnosticAbuse, StagingFiles
| sort by Timestamp desc

Network Indicators & Command-and-Control (C2)

IndicatorTypeContext / Association
osc-cdn[.]comDomainAttacker-controlled spear-phishing SMTP envelope sender
oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]devDomainCloudflare Pages invariant campaign execution tracking beacon
d2nq35tel3ucuo[.]cloudfront[.]netDomainAmazon CloudFront staging endpoint for encrypted JScript/gadgets
pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]devDomainCloudflare R2 staging endpoint for TestAssembly & DLL bundle
pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]devDomainCloudflare R2 staging endpoint for secondary payloads
microsoft-flash[.]comDomainStandalone Antino fake-installer distribution domain
wps-cn[.]comDomainStandalone Antino fake-installer distribution domain
103.27.110[.]220IPv4 AddressHistorical hosting IP for Antino payload on wps-cn[.]com
graph.microsoft.comLegitimate FQDNMicrosoft Graph API endpoint abused for Outlook & OneDrive dead-drop C2
login.microsoftonline.comLegitimate FQDNMicrosoft Entra ID OAuth 2.0 token acquisition endpoint

File System & Hash Telemetry

SHA-256 HashFile / RoleThreat Context
09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cffslc.dllAntino Gen 2 Rust backdoor payload (sideloaded)
e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530slc.dllAntino Gen 2 Rust backdoor variant
1fadc90b61ce536abda78eb387a7f3d745f00c16775d3f762845ccc0fde567daslc.dllAntino Gen 1 Rust backdoor payload
0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bdExecutableAntino Gen 2 standalone fake installer
d753a615aedf8e58ffc75b2b7ebd320c0cbe6bcb5cbb885db749a2a85c55d3bfTestAssembly.dll.NET in-memory downloader (GUID b2b3adb0-...)
f0c1dc6d6daa4d010932c7818ed5f22929c182f58e5f495fabe2fb3cfc835b97JScriptEncrypted JScript orchestrator
e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34HTA StagerCSIS Indo-Pacific Forecast lure stager
f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8HTA StagerTaiwan Legislative tax ruling lure stager
e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcfHTA StagerPhilippine Bajo de Masinloc maritime lure stager
Indicators of Compromise (IOCs)
14 Identified
domainosc-cdn.com
domainoisadjfoinsiduhfnoisdnfosdnoifnsoid.pages.dev
domaind2nq35tel3ucuo.cloudfront.net
domainpub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev
domainpub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev
domainmicrosoft-flash.com
domainwps-cn.com
ip103.27.110.220
hash09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff
hashe2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530
hash1fadc90b61ce536abda78eb387a7f3d745f00c16775d3f762845ccc0fde567da
hashd753a615aedf8e58ffc75b2b7ebd320c0cbe6bcb5cbb885db749a2a85c55d3bf
malwareAntino
threat_actorUAT-11587
// EVERGREEN RELIC // P1 INCIDENT
Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Light mockup

Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Light

“Because nation-state APTs strictly observe your weekend plans.”

Commemorate this cyber event. Printed on ultra-comfortable vintage garment-dyed 100% ring-spun cotton. Engineered for SOC war rooms, late-night incident bridges, and DEFCON.

Direct Armory Fulfillment$25
ACQUIRE RELIC
Fast US Shipping (2-4 Days)• 1-Click Apple / Google Pay
SHARE INTEL:Reddit
OPERATIONS_BROADCAST

Watch Full Video Briefings on YouTube

Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.

SUBSCRIBE_ON_YOUTUBE