Spies target Asian governments with Outlook-run backdoor

Published

The email looked like it carried a Gmail attachment. In fact the attachment card was four small images stitched into the message body and wrapped in a link, and clicking it started a five-stage infection chain that ended with a new backdoor taking its orders from an Outlook mailbox.

That is how Cisco Talos researcher Ashley Shen describes UAT-11587, an activity cluster Talos assesses with high confidence is China-nexus. Active since at least September 2025, it had reached at least 16 affected or targeted institutional environments across eight Asian countries by July 2026, with roughly 350 compromised endpoints. Its main implant, a previously undocumented Rust backdoor, is named Antino after strings in its own developer artifacts.

Governments from Taiwan to Syria

Talos assesses with moderate-to-high confidence that the campaign targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. Victims skew toward defense, foreign affairs, justice and border agencies, legislatures, think tanks and civil society. The largest single wave came on June 8 and 9, 2026, when about 57 newly observed endpoints associated with India appeared. Lures were closely tailored: a workshop on "Taiwan Information Warfare", an exact copy of a Taiwan Ministry of Finance ruling on legislators' expenses, and a fake "CSIS Indo-Pacific Forecast 2026" event brief.

The emails were built to survive a quick look. They went out through the Migadu mail service with the attacker's osc-cdn[.]com domain as the envelope sender, while the visible From line showed the impersonated organization. SPF passed because it only checked the envelope domain. DMARC caught the mismatch, but the impersonated domain's policy was set to p=none, so the message was delivered anyway.

A backdoor that never calls its own server

The fake attachment fetched an HTA file from Cloudflare Pages. Later stages, hosted on Cloudflare R2 and Amazon CloudFront, abuse .NET BinaryFormatter deserialization to load a small downloader inside mshta.exe. That downloader opens a decoy document and drops a Microsoft-signed binary, GatherOsState.exe, which sideloads the Antino DLL, slc.dll.

Antino supports shell and PowerShell execution, file transfer, in-memory shellcode loading and Registry Run persistence. Its command channel runs entirely through Microsoft 365: it checks the operator's Outlook mailbox every 10 seconds for messages whose subjects start with command_req_, and uploads a heartbeat every minute, plus any stolen files, to the operator's OneDrive. On the wire, that traffic ends at graph.microsoft.com and login.microsoftonline.com, destinations most enterprises allow by default.

Why Talos says China, and what it will not say

Talos rests its assessment on the totality of the evidence rather than any single clue: decoys carrying a zh-CN language tag and Simplified Chinese metadata, +08:00 timestamps, ten Antino builds that pulled Rust packages through the China-focused mirror rsproxy.cn, and targeting consistent with Chinese intelligence interests. It found overlaps with Antino-related espionage that Symantec attributes to Jewelbug, the group behind the operation we covered in one control panel ran Chinese spying and crypto fraud. Because Talos could not verify a link to Jewelbug's financially motivated activity, it tracks UAT-11587 as a separate cluster. A CloudFront distribution shared with earlier UNC6384 activity is rated only low confidence.

Block the delivery hosts, then fix p=none

Talos flags the .NET downloader's assembly GUID, b2b3adb0-1669-4b94-86cb-6dd682ddbea3, as a useful tooling-level detection marker, and GatherOsState.exe running from a writable staging folder next to an slc.dll is worth hunting for. Organizations whose domains still publish a DMARC policy of p=none should note that this setting is what let the spoofed messages through. Delivery hosts named in the report include:

The broader lesson is where the traffic went: every step after the click ran through Cloudflare, Amazon and Microsoft, which leaves little for a network defender to block and puts the burden on endpoint and identity telemetry.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions