Antino malware abuses Outlook and OneDrive in Asia-focused espionage

Cisco Talos has identified a previously undocumented Windows backdoor called Antino in an espionage campaign against government and policy organisations across Asia. The activity, tracked as UAT-11587, has targeted 16 entities in eight countries, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand and Myanmar. Talos also found evidence of targeting in Syria around May 2026.
Antino is compiled in Rust and uses Microsoft 365 as its native command-and-control channel. Through Microsoft Graph, the malware uses Outlook for command exchange and OneDrive for heartbeat signals and file transfers, rather than relying on a dedicated command-and-control server. Cisco Talos assesses the operator as China-nexus with high confidence.
Microsoft 365 becomes the command channel
Once active, Antino can perform host reconnaissance, execute shell and PowerShell commands, transfer files, load shellcode in memory and establish persistence. It can list running processes, enumerate directories, run operator-supplied programs and invoke commands through cmd.exe.
For command retrieval, the backdoor polls a threat actor-controlled Outlook mailbox folder every 10 seconds. It searches for messages whose subject begins with command_req_[session_id]. OneDrive is used separately for heartbeat communications and file movement. This design places attacker activity inside commonly used Microsoft 365 services and changes the telemetry defenders need to examine.
Phishing chain combines tailored lures and signed binaries
Talos said the campaign began with spear-phishing and used lures relevant to foreign affairs, international security and government policy. The actor spoofed trusted sender identities to bypass SPF and DMARC checks. In some messages, it rebuilt Gmail's attachment-preview widget in the HTML body with Base64-encoded inline PNG images, then linked the simulated attachment card to an attacker-controlled Cloudflare Pages URL.
The URL delivered an HTA or WSF stager, which retrieved a JavaScript downloader and decryptor. A subsequent .NET deserialization chain loaded TestAssembly.dll, a downloader and launcher that opened a lure document, downloaded a decoy Calculator executable, and launched the Antino backdoor.
The implant, named slc.dll, was launched through DLL sideloading with the legitimate Microsoft-signed GatherOsState.exe binary. Talos also said Antino abuses the Windows Scripted Diagnostics framework to run attacker-controlled PowerShell through legitimate Windows components. While that can complicate attribution to the implant, it does not remove observable PowerShell, file-creation or Registry telemetry.
Attribution signals and defensive implications
Talos found zh-CN language and Simplified Chinese metadata in lure documents, a UTC+08:00 timestamp in phishing headers, Cargo registry paths referencing rsproxy.cn, and a downloader reference to a CloudFront domain previously associated with China-affiliated activity. The researchers noted some overlap with Jewelbug but treated UAT-11587 as a separate activity set after finding no connection to Jewelbug's financially motivated operations.
Attack activity rose between March and early June 2026, including a concentrated wave on June 8 and 9 that targeted dozens of systems associated with government IT infrastructure. Organisations should treat mailbox access, Microsoft Graph activity, PowerShell execution, suspicious file creation and DLL sideloading as connected signals when investigating targeted phishing incidents.

