Image: Cisco Talos
A China-linked campaign has targeted government, defense, research and policy organizations across Asia with a Windows backdoor called Antino. The operation affected or targeted at least 16 institutional environments, with roughly 350 compromised devices identified across eight countries.
Government and policy groups are the main targets
Cisco Talos says the campaign focused on public-sector and national-security-adjacent organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. Targets included government departments, diplomatic services, defense bodies, universities, think tanks and civil society groups.Talos assesses with high confidence that the tracked actor, UAT-11587, has a China nexus. It assesses with moderate confidence that the sustained access and information collection supported an intelligence-gathering operation.
Emails imitate trusted senders and Gmail
Attackers tailored phishing messages to their recipients and sometimes displayed the identity of a trusted organization in the visible From field. In one reviewed message, email authentication detected the mismatch, but the impersonated domain’s monitoring-only DMARC policy allowed delivery.Some emails recreated Gmail’s attachment preview inside the message. The realistic-looking card was actually a link to attacker-controlled Cloudflare Pages infrastructure, where a recipient identifier could be logged.
- Treat an attachment preview as suspicious if clicking it opens a website or downloads an HTA file instead of showing the expected document.
- Organizations in the targeted sectors should review email and endpoint records for oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev and unexpected mshta.exe activity.
- Report messages using unusually specific political, diplomatic, tax or security documents when the sender or delivery method is unexpected.
Antino uses Outlook and OneDrive for control
Antino is a Windows backdoor written in Rust. It can inspect an infected computer, run shell and PowerShell commands, transfer files, load code directly into memory and maintain persistent access.Instead of relying on a conspicuous dedicated command server, the malware communicates through Microsoft 365. It uses Microsoft Graph, a service for accessing Microsoft cloud applications, to exchange data through Outlook and OneDrive objects.
The observed infection chain begins with an HTA file executed by Windows’ mshta.exe component. Later stages load Antino by making the legitimate Microsoft-signed GatherOsState.exe program sideload a malicious slc.dll from the same folder.