AlienVault OTX pulse data, sourced from Cisco Talos research, exposes an active China-nexus intrusion cluster tracked as UAT-11587 conducting sustained espionage operations against government and policy organizations across Asia. Active since at least September 2025, the campaign has confirmed victims in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria — a targeting pattern consistent with intelligence collection against foreign policy, defense, and diplomatic entities aligned against Chinese strategic interests.
The operation delivers Antino, a previously undocumented backdoor written in Rust — a deliberate development choice that complicates reverse engineering, defeats legacy signature engines, and signals a mature, well-resourced development pipeline. Initial access is achieved through tailored spear-phishing against carefully selected individuals in target ministries, policy institutes, NGOs, and educational institutions.
The attack chain is operationally disciplined:
- Spear-phishing delivery of a lure document or archive containing a legitimate signed executable paired with a malicious DLL.
- DLL sideloading executes the Antino loader under the trusted process context of the legitimate binary, evading application control and process-lineage detections.
- Command-and-control over legitimate cloud services — Antino leverages Microsoft 365 infrastructure as a C2 channel and hides staging behind Cloudflare-fronted infrastructure, blending malicious traffic into sanctioned business SaaS flows.
- Persistent espionage — the implant provides remote command execution, file staging, and exfiltration capabilities consistent with long-dwell intelligence collection.
The strategic objective is unambiguous: long-term access to government communications, policy deliberations, and defense-adjacent information across the Indo-Pacific and South Asia.
Threat Actor / Malware Profile
UAT-11587 (China-Nexus Cluster)
UAT-11587 is an unattributed activity cluster assessed by Talos as China-nexus based on targeting geometry, tooling lineage, and operational infrastructure choices. The actor demonstrates:
- Regional focus: Eight Asian nations, weighted toward Taiwan and India — high-priority collection targets for Chinese state intelligence.
- Victimology: Defense, Government, Education, and NGO sectors, specifically policy-shaping organizations rather than financially motivated targets.
- Operational security: Use of Cloudflare fronting and Microsoft 365 as C2 channels — abusing trusted services that defenders cannot categorically block without disrupting business operations.
Antino Backdoor
| Attribute | Detail |
|---|---|
| Language | Rust (compiled) |
| Delivery | Spear-phishing with DLL sideloading chain |
| Execution | Malicious DLL loaded by legitimate signed executable |
| C2 Channel | Microsoft 365 services (e.g., Graph/Exchange/SharePoint APIs); Cloudflare-fronted staging |
| Capabilities | Command execution, file upload/download, host reconnaissance, staged payload delivery |
| Anti-Analysis | Rust compilation (opaque decompilation, stripped symbols), legitimate-process masquerading, encrypted C2 over sanctioned SaaS |
| Persistence | DLL sideloading pairs re-established via dropped artifacts; registry Run keys and service installations observed in comparable Rust implants |
Why Rust matters for defenders: Rust binaries produce large executables with unfamiliar import tables, inlined library code, and no clean function boundaries. YARA rules written for C/C++ implants frequently miss them. Detection must shift toward behavioral signals: the sideloading event itself, the anomalous network egress from a sideloaded host process, and the DLL search-order artifacts on disk.
C2 tradecraft: By routing command traffic through Microsoft 365, Antino inherits TLS encryption, trusted certificates, and high-volume legitimate destinations. NetFlow alone will not surface this. Detection requires process-to-network correlation: a sideloaded or unexpected process authenticating to graph.microsoft.com or *.sharepoint.com outside of sanctioned application patterns is the high-fidelity signal.
IOC Analysis
The pulse contains 90 indicators, with the sample set dominated by SHA-256 file hashes covering Antino payloads, sideloaded DLLs, loader executables, and spear-phishing lure artifacts.
Indicator types and operationalization:
- FileHash-SHA256 — Push into EDR blocklists (Defender custom indicators, CrowdStrike IOC management, SentinelOne blacklist) and proxy/NGFW file-reputation feeds. Hashes are point-in-time; the actor recompiles trivially, so treat them as hunt pivots, not durable prevention.
- Behavioral pivots — Given the hash-heavy indicator set, the durable detection surface is behavioral: DLL sideloading patterns, unsigned DLLs in directories with signed EXEs, and anomalous M365 API traffic from non-standard processes.
Recommended operational workflow:
- Ingest hashes into your SIEM/EDR via the OTX DirectConnect API or TAXII feed with a 30-day TTL.
- Sweep retroactively 90+ days — the campaign has been active since September 2025, so current detections may represent months-old initial access.
- For any hash hit, immediately pivot to the full process tree and network connection history — a hit on the DLL means the loader EXE and C2 traffic exist on that host.
- Enrich hash hits against VirusTotal and your sandbox; Rust binaries with low VT detection rates matching these hashes should be escalated regardless of verdict.
Detection Engineering
---
title: Antino Backdoor - DLL Sideloading via Legitimate Signed Executable
id: 9f3a1c7e-2b4d-4e6a-9c1f-11587aa0001a
status: experimental
description: Detects DLL sideloading patterns consistent with UAT-11587 Antino delivery — an unsigned or untrusted DLL loaded from a non-system directory by a signed executable, matching the campaign's documented execution chain.
author: Security Arsenal Threat Intelligence
date: 2026/09/30
references:
- https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/
logsource:
category: image_load
product: windows
detection_placeholder: null
detection:
selection_signed_parent:
ParentImage|startswith:
- 'C:\Users\'
- 'C:\ProgramData\'
- 'C:\Temp\'
ImageLoaded|endswith: '.dll'
selection_user_writable:
ImageLoaded|contains:
- '\AppData\'
- '\ProgramData\'
- '\Temp\'
- '\Downloads\'
- '\Public\'
filter_signed_dll:
Signed: 'true'
condition: (selection_signed_parent or selection_user_writable) and not filter_signed_dll
fields:
- Image
- ImageLoaded
- ParentImage
- CommandLine
- User
falsepositives:
- Legitimate software installing plugins into user-writable directories
- Developer tooling loading locally built DLLs
level: high
tags:
- attack.defense_evasion
- attack.t1574.002
---
title: Antino C2 - Non-Browser Process Communication with Microsoft 365 API Endpoints
id: 9f3a1c7e-2b4d-4e6a-9c1f-11587aa0002b
status: experimental
description: UAT-11587's Antino backdoor uses Microsoft 365 infrastructure as a C2 channel. Detects non-standard processes initiating connections to M365 API endpoints outside of sanctioned application binaries.
author: Security Arsenal Threat Intelligence
date: 2026/09/30
references:
- https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/
logsource:
category: network_connection
product: windows
detection:
selection_dest:
DestinationHostname|contains:
- 'graph.microsoft.com'
- 'login.microsoftonline.com'
- '.sharepoint.com'
- '.office365.com'
- 'outlook.office.com'
Initiated: 'true'
filter_sanctioned:
Image|endswith:
- '\msedge.exe'
- '\chrome.exe'
- '\firefox.exe'
- '\OUTLOOK.EXE'
- '\Teams.exe'
- '\OneDrive.exe'
- '\explorer.exe'
- '\svchost.exe'
- '\powershell.exe'
condition: selection_dest and not filter_sanctioned
fields:
- Image
- DestinationHostname
- DestinationIp
- User
- CommandLine
falsepositives:
- Custom line-of-business applications using Graph API
- Backup or compliance tooling syncing to M365
level: high
tags:
- attack.command_and_control
- attack.t1102
- attack.t1071.001
---
title: Suspicious Rust-Compiled Unsigned Binary Execution from User Directory
id: 9f3a1c7e-2b4d-4e6a-9c1f-11587aa0003c
status: experimental
description: Detects execution of unsigned PE binaries with Rust-compilation artifact strings from user-writable paths — consistent with Antino payload staging. Rust binaries frequently embed cargo path strings and panic-handling markers.
author: Security Arsenal Threat Intelligence
date: 2026/09/30
references:
- https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/
logsource:
category: process_creation
product: windows
detection:
selection_path:
Image|contains:
- '\AppData\Local\Temp\'
- '\AppData\Roaming\'
- '\ProgramData\'
- '\Users\Public\'
- '\Downloads\'
selection_unsigned:
Signed: 'false'
filter_known_good:
Image|contains:
- '\Microsoft\'
- '\Google\'
- '\Mozilla\'
condition: selection_path and selection_unsigned and not filter_known_good
fields:
- Image
- CommandLine
- ParentImage
- Hashes
- User
falsepositives:
- Portable applications run from Downloads
- User-installed development tools
level: medium
tags:
- attack.execution
- attack.t1059
- attack.defense_evasion
- attack.t1027
// UAT-11587 / Antino Hunt: IOC hash sweep + behavioral pivots
// Run retroactively back to 2025-09-01 (campaign start)
let AntinoHashes = dynamic([
"e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf",
"01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a",
"e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34",
"f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8",
"e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530",
"e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb",
"09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff",
"b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e"
]);
let M365C2 = dynamic(["graph.microsoft.com","login.microsoftonline.com",".sharepoint.com","outlook.office.com"]);
// Part 1: Direct hash matches on file creation / process execution
let HashHits = union isfuzzy=true
(DeviceFileEvents | where SHA256 in (AntinoHashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine),
(DeviceProcessEvents | where SHA256 in (AntinoHashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, ProcessCommandLine, InitiatingProcessFileName);
// Part 2: Behavioral — unsigned DLL loads from user-writable dirs (sideloading)
let SideloadBehavior = DeviceImageLoadEvents
| where FolderPath has_any ("\\AppData\\","\\ProgramData\\","\\Temp\\","\\Downloads\\","\\Public\\")
| where FolderPath endswith ".dll"
| where IsSigned == false or isempty(IsSigned)
| where InitiatingProcessFolderPath has_any ("\\Users\\","\\ProgramData\\","\\Temp\\")
| summarize DLLsLoaded = make_set(FileName), FirstSeen = min(Timestamp), LastSeen = max(Timestamp)
by DeviceName, InitiatingProcessFileName, InitiatingProcessSHA256;
// Part 3: Behavioral — non-standard processes talking to M365 API endpoints
let M365Anomalous = DeviceNetworkEvents
| where RemoteUrl has_any (M365C2)
| where InitiatingProcessFileName !in~ ("msedge.exe","chrome.exe","firefox.exe","OUTLOOK.EXE","Teams.exe","OneDrive.exe","svchost.exe","explorer.exe")
| where InitiatingProcessFolderPath has_any ("\\AppData\\","\\ProgramData\\","\\Temp\\","\\Users\\Public\\")
| summarize Connections = count(), RemoteUrls = make_set(RemoteUrl), RemoteIPs = make_set(RemoteIP), FirstSeen = min(Timestamp), LastSeen = max(Timestamp)
by DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine;
HashHits
| union (SideloadBehavior), (M365Anomalous)
| order by Timestamp desc
# UAT-11587 / Antino IOC & Artifact Hunt — Security Arsenal
# Run as Administrator on suspect endpoints or deploy via EDR live response / GPO scheduled task
# Checks: Antino hashes, sideloading artifacts, persistence keys, M365 C2 connections
$ErrorActionPreference = 'SilentlyContinue'
$report = @()
# --- Known Antino SHA-256 indicators (from OTX pulse) ---
$AntinoHashes = @(
'e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf',
'01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a',
'e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34',
'f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8',
'e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530',
'e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb',
'09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff',
'b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e'
)
Write-Host "[1/5] Hashing files in high-risk staging directories..." -ForegroundColor Cyan
$scanPaths = @("$env:APPDATA","$env:LOCALAPPDATA\Temp","$env:ProgramData","C:\Users\Public","$env:USERPROFILE\Downloads")
foreach ($path in $scanPaths) {
Get-ChildItem -Path $path -Recurse -Include *.exe,*.dll -ErrorAction SilentlyContinue | ForEach-Object {
$h = (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower()
if ($AntinoHashes -contains $h) {
$report += [PSCustomObject]@{Type='IOC-HASH-HIT'; Path=$_.FullName; Detail=$h; Severity='CRITICAL'}
}
# Flag unsigned DLLs in user-writable dirs (sideloading surface)
if ($_.Extension -eq '.dll') {
$sig = Get-AuthenticodeSignature $_.FullName
if ($sig.Status -ne 'Valid') {
$report += [PSCustomObject]@{Type='UNSIGNED-DLL'; Path=$_.FullName; Detail='Possible sideload staging'; Severity='HIGH'}
}
}
}
}
Write-Host "[2/5] Checking persistence mechanisms (Run keys, services, tasks)..." -ForegroundColor Cyan
$runKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run')
foreach ($key in $runKeys) {
Get-ItemProperty $key | ForEach-Object {
$_.PSObject.Properties | Where-Object { $_.Value -match 'AppData|ProgramData|Temp|Public' -and $_.Name -notmatch '^PS' } | ForEach-Object {
$report += [PSCustomObject]@{Type='PERSISTENCE-RUNKEY'; Path="$key\$($_.Name)"; Detail=$_.Value; Severity='HIGH'}
}
}
}
Get-ScheduledTask | Where-Object { $_.Actions.Execute -match 'AppData|ProgramData|Temp' } | ForEach-Object {
$report += [PSCustomObject]@{Type='PERSISTENCE-TASK'; Path=$_.TaskName; Detail=$_.Actions.Execute; Severity='HIGH'}
}
Write-Host "[3/5] Checking active connections to M365/Cloudflare C2 infrastructure..." -ForegroundColor Cyan
Get-NetTCPConnection -State Established | ForEach-Object {
$proc = Get-Process -Id $_.OwningProcess
if ($proc.Path -match 'AppData|ProgramData|Temp|Users\\Public') {
try {
$rdns = ([System.Net.Dns]::GetHostEntry($_.RemoteAddress)).HostName
} catch { $rdns = 'unresolved' }
if ($rdns -match 'microsoft|office|sharepoint|cloudflare' -and $proc.ProcessName -notmatch 'edge|chrome|firefox|outlook|teams|onedrive') {
$report += [PSCustomObject]@{Type='C2-ANOMALY'; Path=$proc.Path; Detail="$($_.RemoteAddress):$($_.RemotePort) [$rdns]"; Severity='CRITICAL'}
}
}
}
Write-Host "[4/5] Checking for large unsigned Rust-style binaries (>4MB, unsigned, user dirs)..." -ForegroundColor Cyan
foreach ($path in $scanPaths) {
Get-ChildItem -Path $path -Recurse -Include *.exe -ErrorAction SilentlyContinue | Where-Object { $_.Length -gt 4MB } | ForEach-Object {
$sig = Get-AuthenticodeSignature $_.FullName
if ($sig.Status -ne 'Valid') {
$report += [PSCustomObject]@{Type='SUSPICIOUS-BINARY'; Path=$_.FullName; Detail="Size: $([math]::Round($_.Length/1MB,1))MB, unsigned — consistent with Rust payload profile"; Severity='MEDIUM'}
}
}
}
Write-Host "[5/5] Compiling report..." -ForegroundColor Cyan
if ($report.Count -gt 0) {
$report | Sort-Object Severity | Format-Table -AutoSize
$report | Export-Csv -Path "C:\UAT11587_Hunt_$(Get-Date -Format 'yyyyMMdd_HHmmss').csv" -NoTypeInformation
Write-Host "[!] $($report.Count) findings — isolate host and escalate to IR immediately if CRITICAL." -ForegroundColor Red
} else {
Write-Host "[+] No UAT-11587 / Antino artifacts detected on this host." -ForegroundColor Green
}
Response Priorities
Immediate (0–4 hours)
- Block all 90 IOC hashes across EDR, email gateway, and web proxy. Deploy the Sigma rules and KQL queries to production.
- Sweep retroactively to 2025-09-01 — the campaign has run for over a year; any hash hit likely indicates long-dwell access requiring full forensic scoping, not simple remediation.
- Audit M365 API access: review Graph API app registrations and OAuth consent grants for unauthorized third-party applications — Antino's C2 channel may ride legitimate tenant authentication.
- For government, defense, NGO, and education sector organizations in the eight named countries: elevate to incident posture and initiate proactive threat hunting immediately.
24 Hours
- Force credential resets for all users on any host with a confirmed hash or behavioral hit — APT implants of this class routinely harvest tokens and cached credentials to enable lateral movement and M365 persistence.
- Revoke all active sessions and refresh tokens in Entra ID/M365 for affected users; audit mailbox rules and delegated access for attacker-established persistence.
- Review Cloudflare-fronted traffic from endpoints: identify any non-standard processes egressing to Cloudflare IP space and cross-reference against the C2 behavioral query above.
- Interview targeted users for spear-phishing lures; preserve original emails and attachments for malware analysis.
1 Week
- Deploy application control (WDAC/AppLocker) blocking unsigned DLL loads from user-writable directories — this directly breaks the Antino sideloading chain.
- Restrict M365 API access to sanctioned application IDs via conditional access and app governance policies; alert on Graph API calls from unmanaged devices or non-standard user agents.
- Implement DLL search-order hardening and audit directories where signed executables coexist with writable DLL paths.
- Add Rust-binary detection coverage to sandbox and YARA pipelines; the hash-based indicator model is insufficient against a recompiling adversary.
- Brief executive leadership on the espionage risk profile — for targeted-sector organizations, assume collection intent against policy deliberations and sensitive communications.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.