Full Report
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.
Analysis Summary
# Threat Actor: UAT-11587
## Attribution & Identity
* **Identification:** UAT-11587 is a China-nexus threat actor.
* **Aliases/Associations:**
* **Jewelbug:** Overlaps with espionage activity reported by Symantec under this name. (Note: Talos tracks UAT-11587 separately as it could not verify the link to Jewelbug's financially motivated/crypto-fraud activity).
* **UNC6384:** Potential infrastructure overlap (CloudFront distribution) with this China-nexus delivery group.
* **Attribution Indicators:**
* Metadata in decoy documents contains `zh-CN` language tags and Simplified Chinese characters ("未定义").
* Consistent use of UTC+8 (+08:00) timestamps.
* Development artifacts for the "Antino" backdoor reference `rsproxy.cn`, a Rust package mirror specifically intended for users within mainland China.
## Activity Summary
First observed in September 2025, UAT-11587’s activities escalated through mid-2026. A major campaign identified in March 2026 targeted Taiwan’s academic and policy sectors. By July 2026, the actor had targeted at least 16 institutional environments across eight Asian countries. The operations typically involve sophisticated spear-phishing and multi-stage infection chains to deploy a custom Rust-based backdoor.
## Tactics, Techniques & Procedures
* **Initial Access:** Spear-phishing emails using tailored decoy documents and recreated Gmail attachment interfaces.
* **Execution & Persistence:** Multi-stage infection chains (five stages) including JavaScript downloaders and BinaryFormatter resources.
* **DLL Side-Loading:** Use of legitimate executables (e.g., `GatherOsState.exe`) to load malicious DLLs (`slc.dll`).
* **C2 Communication:** Utilizes Microsoft 365 (Outlook and OneDrive) via Microsoft Graph API as a "dead drop" for command-and-control, avoiding dedicated C2 servers.
* **Evasion:** Heavy reliance on legitimate cloud services (Cloudflare, Microsoft 365, CloudFront) to blend in with normal traffic.
* **MITRE ATT&CK IDs (Inferred/Implicit):**
* T1566 (Phishing)
* T1574.002 (DLL Side-Loading)
* T1102.002 (Web Service: Bidirectional Communication)
* T1071.004 (Application Layer Protocol: DNS)
* T1059.001 (PowerShell)
## Targeting
* **Sectors:** Government, policy organizations, think tanks, academic institutions, maritime, diplomatic, and civil defense.
* **Geography:** Primarily Asia (Taiwan, India, Philippines, Cambodia, and four other unnamed Asian countries).
* **Victims:** Policy research communities, regional government agencies, and security environments.
## Tools & Infrastructure
* **Malware:**
* **Antino:** A custom Windows backdoor compiled in Rust. Features include host reconnaissance, file transfer, shell/PowerShell execution, and in-memory shellcode loading.
* **Infrastructure:**
* **Microsoft 365:** Outlook/OneDrive used for C2.
* **Cloudflare R2/Workers:** Used for delivery, execution tracking, and payload staging.
* **Defanged IOCs:**
* d32tpl7xt7175h[.]cloudfront[.]net
* pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev
* pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev
* hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/7ChyKauxbnuftp68.js
## Implications
UAT-11587 represents a highly capable espionage threat focused on regional geopolitical intelligence. By utilizing Rust for malware development and Microsoft Graph for C2, the actor significantly increases the difficulty of detection and analysis. Their ability to leverage trusted cloud infrastructure (Cloudflare, AWS, Microsoft) indicates a strategic shift toward "living-off-the-cloud" to bypass traditional perimeter security.
## Mitigations
* **Email Security:** Implement advanced phishing protection to detect look-alike interfaces and malicious cloud-hosted links.
* **Endpoint Monitoring:** Monitor for suspicious side-loading behaviors, specifically legitimate Windows binaries loading unexpected DLLs from non-standard paths.
* **Cloud Visibility:** Monitor Microsoft Graph API activity and Microsoft 365 logs for unusual patterns, such as unexpected OneDrive/Outlook interactions originating from system processes.
* **Network Filtering:** Block or scrutinize traffic to known R2 storage buckets and unusual CloudFront distributions not associated with business needs.