UAT-11587 Targets Asian Government and Policy Organizations with Antino Backdoor
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
UAT-11587, a China-nexus threat actor, is conducting cyber espionage operations against government, policy, and national security organizations across Asia. The group employs a five-stage infection chain to deliver Antino, a custom Rust-compiled Windows backdoor. The malware abuses Microsoft 365 services, particularly Outlook and OneDrive, to establish dead-drop command-and-control (C2) communication.
Investigation
Cisco Talos traced the malicious activity to an initial spear-phishing campaign targeting Taiwan. Researchers reconstructed a multi-stage infection chain incorporating HTA/WSF stagers, JScript downloaders, and .NET deserialization exploitation. Further analysis revealed the abuse of Cloudflare and Amazon CloudFront infrastructure for payload staging, alongside distinctive development artifacts embedded within the Antino malware.
Mitigation
Organizations should monitor suspicious execution of mshta.exe and wscript.exe, particularly when these processes interact with cloud storage platforms. Enforcing strict DMARC policies can reduce exposure to sender domain spoofing. Security teams should also investigate anomalous Microsoft Graph API activity, including unexpected Outlook and OneDrive interactions that may indicate malicious C2 communication.
Response
If Antino activity is detected, affected endpoints should be isolated immediately to contain potential lateral movement and data exfiltration. Conduct memory forensics to uncover in-memory shellcode and injected .NET assemblies. Examine Microsoft 365 audit logs for unauthorized access through OAuth 2.0 client-credentials flows, and investigate suspicious modifications to mailbox contents or OneDrive objects.
Attack Flow
We are still updating this part.
Detections
Suspicious LOLBAS MSHTA Defense Evasion Behavior by Detection of Associated Commands (via process_creation)
LOLBAS WScript / CScript (via process_creation)
Microsoft Graph API Domain Resolved By Unusual Process (via dns_query)
Possible Cloudflare Development Domain Abuse (via dns)
IOCs (HashSha256) to detect: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor Part 3
IOCs (HashSha256) to detect: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor Part 2
IOCs (HashSha256) to detect: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor Part 1
IOCs (SourceIP) to detect: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
IOCs (DestinationIP) to detect: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Powershell Execution from Windows Diagnostics by Antino Backdoor [Windows Powershell]
Detection of Antino C2 Communication via Microsoft 365 [Windows Network Connection]
UAT-11587 Antino Backdoor Spear-Phishing Detection [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: An adversary has established initial access on a Windows workstation. To maintain control without triggering traditional firewall alerts, the attacker deploys a lightweight stager that communicates with the Microsoft Graph API. The stager uses a simple PowerShell loop to reach out to
graph.microsoft.com, masquerading as an automated process fetching data from an Outlook mailbox or OneDrive folder. This allows the attacker to download further modules or receive commands via API responses, successfully blending into the organization’s legitimate Microsoft 365 traffic. -
Regression Test Script:
# Simulation of Antino C2 communication via Microsoft Graph API # This script mimics a process making an outbound HTTPS request to the target domain. $TargetUrl = "https://graph.microsoft.com/v1.0/me" Write-Host "[+] Starting C2 Simulation: Connecting to $TargetUrl" -ForegroundColor Cyan try { # Using Invoke-WebRequest to generate a standard Network Connection event $response = Invoke-WebRequest -Uri $TargetUrl -Method Get -UseBasicParsing Write-Host "[+] Connection Successful. Telemetry should be generated." -ForegroundColor Green } catch { Write-Host "[-] Connection failed (this is expected if the environment lacks auth, but telemetry should still trigger)." -ForegroundColor Yellow } -
Cleanup Commands:
# No persistence is created by this script. # Simply clear the console to signify end of test. Clear-Host Write-Host "[+] Simulation Cleanup Complete." -ForegroundColor Green