INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Antino Backdoor Exploits Outlook and OneDrive for China-Nexus Espionage

| 2026-09-30 11:57 MEDIUM HIGH MALWARE & BOTNETS STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A China-linked group, identified as UAT-11587, has been using the Antino backdoor and Microsoft 365 to spy on Asian governments since at least September 2025. The attackers created highly targeted documents that suggested they had researched their victims, including a fake workshop document about Taiwan's information warfare and a document that closely copied a real Taiwan Ministry of Finance ruling. They used phishing emails with convincing content, spoofing legitimate domains and exploiting gaps in email security measures to deliver the malware. Once inside Microsoft 365, Antino hid by using Microsoft Graph to read commands from an Outlook mailbox and send stolen files to OneDrive, allowing its traffic to blend in with normal activity. By July 2026, UAT-11587 had hit at least 16 government and policy organizations across eight Asian countries.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
ca14ad••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
7c2ac9••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
ae1b45••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
b31ca7••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
my•••••.dev
d2•••••.net
my•••••.dev
my•••••.dev
Te•••••.dll
hj•••••.dll
oa•••••.txt
gp•••••.txt
28f754••••••••••••••••••••••••••
5510d3••••••••••••••••••••••••••
66b403••••••••••••••••••••••••••
cc648b••••••••••••••••••••••••••
103.27.•••.•••
e3b2bb••••••••••••••••••••••••••••••••••
13425b••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CarbonCarbon
Target & Sectors
ASEAN ASEAN SOUTH_ASIA SOUTH_ASIA NORTH_AMERICA NORTH_AMERICA governmentgovernment
Incident Timeline
‎June 8 and 9, 2026
Threat actors used the Antino backdoor to mount a concentrated wave of attacks on government IT infrastructure systems associated with dozens of organizations across Asia.
industry Government
‎June 8 and 9
Threat actors using the Antino backdoor targeted government and policy organizations across Asia, with a concentrated wave of 57 newly observed endpoints associated with India occurring on June 8 and 9.
infrastructure 57 new endpoints
source_region India
‎September 2025
A China-nexus threat cluster designated UAT-11587 has been targeting government and policy organizations across eight Asian countries since September 2025, delivering a previously undocumented Rust-compiled backdoor called Antino.
source_region China
industry Government
industry Defense
infrastructure Microsoft 365
general_metric 365 services
infrastructure Windows
organisation Cyber Security News
target_region Taiwan, Province of China
tactic Phishing
tactic Espionage
general_metric 16 entities
‎2025/10/02
Threat actors associated with UNC6384 used a CloudFront domain to host a JavaScript downloader that targeted government and policy organizations across Asia.
industry Government
infrastructure Windows
attribution UNC6384
‎January 2026
Threat actors used Antino backdoor to target government and policy organizations across Asia, including a Philippines-focused campaign in January 2026.
target_region Philippines
organisation HTML
organisation HTA
‎March 2026
Threat actors using UAT-11587's campaign spear-phished Taiwan's academic, think tank, and civil society policy community in March 2026.
tactic Phishing
source_region Taiwan, Province of China
organisation UAT-11587’s
‎May 2026
Threat actors using the China-nexus UAT-11587 backdoor targeted government and policy organizations across Asia with Antino, later shifting focus to organizations in Syria around May 2026.
target_region Syrian Arab Republic
‎May 27
Threat actors used Antino backdoor to target government and policy organizations across Asia following a Tehran-based bilateral meeting.
organisation TPiE   Regional
‎July 2026
Threat actors using the Antino backdoor targeted at least 16 government and policy organizations across eight Asian countries with espionage activity cluster UAT-11587.
industry Government
tactic Espionage
general_metric 16 entities
general_metric 10 seconds
‎August 2026
Threat actors affiliated with the China-based hackers-for-hire group Jewelbug used Antino backdoor to target government and policy organizations across Asia.
tactic Espionage
target_region China
malware Carbon
‎between March and early June 2026
Threat actors used Antino backdoor to target government and policy organizations across Asia between March and early June 2026.
industry Government
‎September through November 2025
Threat actors used Philippines-themed lures and direct email attachment delivery to target government and policy organizations across Asia with the China-nexus UAT-11587 malware, which included an Antino backdoor.
target_region Philippines
‎September 2025 through July 2026
Threat actors used the China-nexus UAT-11587 campaign to target government and policy organizations across Asia with an Antino backdoor from September 2025 through July 2026.
‎December 2025 to January 2026
Threat actors used the Antino backdoor to target government and policy organizations across Asia during December 2025 to January 2026.
‎2026/09/30
Threat actors used Antino backdoor to target government and policy organizations across Asia with Microsoft 365 for post-compromise C2.
organisation Antino Backdoor Uses Outlook
organisation OneDrive
organisation China-Nexus Espionage Campaign
infrastructure Microsoft 365
organisation Antino Backdoor Lets China-Linked UAT-11587
organisation Antino
organisation CloudFront
organisation UNC6384
infrastructure Windows
organisation Taiwan Ministry of Finance
organisation Traditional Chinese
organisation the “Taiwan Information Warfare
infrastructure 350 compromised endpoints
infrastructure 57 new endpoints
organisation SEO
organisation Cloudflare
organisation Microsoft
organisation Outlook
organisation Microsoft Graph
organisation Earth Alux
organisation Outlook for command exchange
organisation DLL
organisation the Windows Scripted Diagnostics
organisation HTA
organisation Windows Script Host
organisation Windows Assessment and Deployment Kit
organisation AntinoApp
organisation PDB
organisation CI
organisation PCW
organisation Cloudflare R2
organisation Registry
organisation HTML
organisation PE
organisation PNG
organisation MIME
organisation Cloudflare Pages
organisation Amazon CloudFront
organisation Associated Press
organisation VirusTotal
organisation SecurityAffairs
organisation JScript
organisation Microsoft JScript
organisation hxxps://microsoft-flash[.]com
organisation IP
organisation osc-cdn[.]com
organisation microsoft-flash[.]com
infrastructure 2 standalone installer backdoor
organisation Stage 2
organisation UUID
organisation The Scripted Diagnostics
organisation SMTP
organisation DMARC
organisation TikTok
organisation Indo-Pacific
organisation BinaryFormatter
organisation TestAssembly
organisation Entra ID
organisation request_id
organisation VirtualAlloc
organisation VEH
organisation add_to_run
organisation ClamAV
organisation Snort
financial 2 Txt
financial 5 Txt
financial 1 Win
Tactical Metrics
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
350
Compromised Endpoints
Metrics
infrastructure
57
New Endpoints
Metrics
infrastructure
2
Standalone Installer Backdoor
Metrics
financial
2
Txt
Metrics
financial
5
Txt
Metrics
financial
1
Win