SOC Prime Bias: High

01 Oct 2026 08:24 UTC

UAT-11587 Targets Asian Government and Policy Organizations with Antino Backdoor

Author Photo
SOC Prime Team linkedin icon Follow
UAT-11587 Targets Asian Government and Policy Organizations with Antino Backdoor
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

UAT-11587, a China-nexus threat actor, is conducting cyber espionage operations against government, policy, and national security organizations across Asia. The group employs a five-stage infection chain to deliver Antino, a custom Rust-compiled Windows backdoor. The malware abuses Microsoft 365 services, particularly Outlook and OneDrive, to establish dead-drop command-and-control (C2) communication.

Investigation

Cisco Talos traced the malicious activity to an initial spear-phishing campaign targeting Taiwan. Researchers reconstructed a multi-stage infection chain incorporating HTA/WSF stagers, JScript downloaders, and .NET deserialization exploitation. Further analysis revealed the abuse of Cloudflare and Amazon CloudFront infrastructure for payload staging, alongside distinctive development artifacts embedded within the Antino malware.

Mitigation

Organizations should monitor suspicious execution of mshta.exe and wscript.exe, particularly when these processes interact with cloud storage platforms. Enforcing strict DMARC policies can reduce exposure to sender domain spoofing. Security teams should also investigate anomalous Microsoft Graph API activity, including unexpected Outlook and OneDrive interactions that may indicate malicious C2 communication.

Response

If Antino activity is detected, affected endpoints should be isolated immediately to contain potential lateral movement and data exfiltration. Conduct memory forensics to uncover in-memory shellcode and injected .NET assemblies. Examine Microsoft 365 audit logs for unauthorized access through OAuth 2.0 client-credentials flows, and investigate suspicious modifications to mailbox contents or OneDrive objects.

Attack Flow

We are still updating this part.

Detections

Suspicious LOLBAS MSHTA Defense Evasion Behavior by Detection of Associated Commands (via process_creation)

SOC Prime Team
30 Sep 2026

LOLBAS WScript / CScript (via process_creation)

SOC Prime Team
30 Sep 2026

Microsoft Graph API Domain Resolved By Unusual Process (via dns_query)

SOC Prime Team
30 Sep 2026

Possible Cloudflare Development Domain Abuse (via dns)

SOC Prime Team
30 Sep 2026

IOCs (HashSha256) to detect: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor Part 3

SOC Prime AI Rules
30 Sep 2026

IOCs (HashSha256) to detect: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor Part 2

SOC Prime AI Rules
30 Sep 2026

IOCs (HashSha256) to detect: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor Part 1

SOC Prime AI Rules
30 Sep 2026

IOCs (SourceIP) to detect: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

SOC Prime AI Rules
30 Sep 2026

IOCs (DestinationIP) to detect: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

SOC Prime AI Rules
30 Sep 2026

Powershell Execution from Windows Diagnostics by Antino Backdoor [Windows Powershell]

SOC Prime AI Rules
30 Sep 2026

Detection of Antino C2 Communication via Microsoft 365 [Windows Network Connection]

SOC Prime AI Rules
30 Sep 2026

UAT-11587 Antino Backdoor Spear-Phishing Detection [Windows Process Creation]

SOC Prime AI Rules
30 Sep 2026

Simulation Execution

  • Attack Narrative & Commands: An adversary has established initial access on a Windows workstation. To maintain control without triggering traditional firewall alerts, the attacker deploys a lightweight stager that communicates with the Microsoft Graph API. The stager uses a simple PowerShell loop to reach out to graph.microsoft.com, masquerading as an automated process fetching data from an Outlook mailbox or OneDrive folder. This allows the attacker to download further modules or receive commands via API responses, successfully blending into the organization’s legitimate Microsoft 365 traffic.

  • Regression Test Script:

      # Simulation of Antino C2 communication via Microsoft Graph API
      # This script mimics a process making an outbound HTTPS request to the target domain.
    
      $TargetUrl = "https://graph.microsoft.com/v1.0/me"
      Write-Host "[+] Starting C2 Simulation: Connecting to $TargetUrl" -ForegroundColor Cyan
    
      try {
          # Using Invoke-WebRequest to generate a standard Network Connection event
          $response = Invoke-WebRequest -Uri $TargetUrl -Method Get -UseBasicParsing
          Write-Host "[+] Connection Successful. Telemetry should be generated." -ForegroundColor Green
      }
      catch {
          Write-Host "[-] Connection failed (this is expected if the environment lacks auth, but telemetry should still trigger)." -ForegroundColor Yellow
      }
  • Cleanup Commands:

      # No persistence is created by this script. 
      # Simply clear the console to signify end of test.
      Clear-Host
      Write-Host "[+] Simulation Cleanup Complete." -ForegroundColor Green