China's UAT-11587 Targets Asian Governments via Antino Backdoor

SOC Briefing Summary :: Executive Key Takeaways
- [01]China-nexus threat cluster UAT-11587 compromised 350+ endpoints across 16+ government and policy institutions in 8 Asian countries using the custom Antino Rust backdoor.
- [02]Attackers cloned Gmail attachment preview widgets and exploited .NET BinaryFormatter deserialization to load payloads via signed Windows ADK DLL sideloading.
- [03]Immediate action: Audit Entra ID OAuth application permissions for unauthorized Mail/Files Graph API scopes and block executable sideloading of GatherOsState.exe.
Executive Summary
Cisco Talos has uncovered a persistent, highly targeted cyber espionage campaign attributed with high confidence to the China-nexus threat cluster UAT-11587. Operating continuously from at least September 2025 through July 2026, the threat actors penetrated more than 16 confirmed or probable public-sector and national security-adjacent institutional environments across eight Asian nations—including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. Telemetry corroborates approximately 350 compromised endpoints across targeted foreign affairs ministries, defense establishments, parliamentary bodies, and civil society think tanks.
The intrusion lifecycle centers on the deployment of Antino, a previously undocumented, high-capability Windows backdoor compiled in Rust. Rather than maintaining dedicated command-and-control (C2) servers that trigger perimeter alerts, Antino communicates natively and exclusively through Microsoft 365. By abusing the Microsoft Graph API via OAuth 2.0 client-credentials authentication, the implant interacts with threat actor-controlled Outlook mailboxes and OneDrive folders as dead drops, polling for operator commands every 10 seconds and synchronizing exfiltrated data every minute.
UAT-11587's delivery mechanics exhibit remarkable tradecraft. The threat actors abused SMTP sender domain misalignment to bypass non-enforcing DMARC policies and cloned the exact HTML preview card of Google Gmail's native attachment widget. The resulting multi-stage chain weaponized in-memory .NET BinaryFormatter deserialization gadget chains and DLL sideloading through Microsoft's signed Windows Assessment and Deployment Kit (ADK) binary GatherOsState.exe.
Technical Vulnerability Analysis & Attack Chain

Stage 1: Sender Spoofing & Gmail Widget Cloning
- Sender Domain Misalignment: UAT-11587 routed spear-phishing emails through Migadu infrastructure, designating the attacker-controlled
osc-cdn[.]comdomain as the RFC5321 envelope sender. While this allowed messages to pass SPF authentication cleanly, the RFC5322 visibleFromheader displayed the trusted identity of target organizations. Because target organizations maintained non-enforcing DMARC monitoring policies (p=none), recipient gateways accepted and delivered the spoofed messages despite DMARC validation failure. - HTML Attachment Card Emulation: In attacks targeting Gmail users, the operators embedded four Base64-encoded PNG images directly into the email HTML body, perfectly replicating Gmail's native attachment card interface. Clicking the preview redirected victims to protocol-relative Cloudflare Pages URLs formatted as
//my-<project>.pages.dev/File_download?m=<target-id>, allowing attackers to log execution per victim. - Geopolitical & Policy Decoys: Decoys were rigorously customized to target institutions. Samples included Taiwan Ministry of Finance legislative tax rulings (
GL005442), Taiwan information warfare studies referencing TikTok, CSIS Indo-Pacific Forecast 2026 event schedules targeting Indian policy circles, and Philippine maritime dispute resolutions concerning Bajo de Masinloc (Scarborough Shoal).
Stage 2: Cloudflare Stager & HTA Ingress
- Living-off-the-Land Ingress: The Cloudflare Pages URL initiated the download of an HTML Application (
.HTA) or Windows Script File (.WSF), executed via native Windows utilitiesmshta.exeorwscript.exe. - Execution Telemetry Beacon: Upon launch, the stager resized and hid its window, transmitting an HTTP GET request containing the lure title in the URI path to a fixed Cloudflare Pages telemetry hostname (
oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev) to track successful victim detonations. - Encrypted Payload Retrieval: The stager pulled three encrypted staging assets from Cloudflare R2 (
pub-<hex>.r2[.]dev) or Amazon CloudFront (d2nq35tel3ucuo[.]cloudfront[.]net): an encrypted JScript orchestrator (.js) and two encrypted .NET serialized gadget files (.txt). The stager applied custom Base64 decoding and decrypted each asset using RC4 with embedded keys.
Stage 3: .NET BinaryFormatter In-Memory Deserialization Chain
- Scripted Gadget Chain Execution: The decrypted JScript instantiated COM-visible .NET 4.x runtime classes directly within
mshta.exeand passed attacker-controlled streams intoBinaryFormatter.Deserialize. - Two-Stage Deserialization Bypass:
- Stage 1: Deserializes an assembly designed to bypass .NET Framework security mitigations introduced to restrict
ActivitySurrogateSelectorgadget chains. The code executed in atry/catchblock to handle discrepancies across patch levels. - Stage 2: Leveraged the
System.Windows.Forms.AxHost+Stategadget coupled withActivitySurrogateSelectorto load an embedded PE file—TestAssembly.dll(GUIDb2b3adb0-1669-4b94-86cb-6dd682ddbea3)—directly intomshta.exeprocess memory without writing bytes to disk.
- Stage 1: Deserializes an assembly designed to bypass .NET Framework security mitigations introduced to restrict
Stage 4: Signed Host ADK DLL Sideloading
- Staging Package Retrieval:
TestAssembly.dllacted as an in-memory launcher, downloading a decoy document and a three-file bundle disguised with arbitrary extensions (.luy,.pzs,.syk) from Cloudflare R2. - ADK Binary Abuse: The downloader wrote the bundle to a user-writable directory (
%LOCALAPPDATA%\Windows GatherOSStateKit\) and launchedGatherOsState.exe, a legitimate Microsoft-signed Windows Assessment and Deployment Kit (ADK) binary. - DLL Hijacking:
GatherOsState.exeautomatically sideloadedslc.dllfrom its current working directory, calling the exported functionSLOpento transfer execution to the Antino backdoor runtime.
Stage 5: Antino Rust Backdoor Architecture & M365 C2
- Compilation & Heritage: Antino is an advanced Windows backdoor authored in Rust, identified across 32-bit and 64-bit builds. PDB paths reveal development inside GitHub Actions Windows runners (
D:\a\antino\antino\target\...) and dependency downloads sourced from Chinese Rust mirrorrsproxy.cn. - Microsoft 365 Graph Dead-Drop C2: Antino does not maintain outbound connections to proprietary IP addresses. Instead, it authenticates to Microsoft Graph (
graph.microsoft.com) and Microsoft Online (login.microsoftonline.com) using OAuth 2.0 client credentials:- Outlook Command Channel: Every 10 seconds, Antino queries the attacker's Outlook inbox for messages with subject
command_req_[session_id]. It parses JSON tasking (cmd,powershell,load_shellcode,system_info), executes the directive, and replies withcommand_res_[session_id]. - OneDrive File & Heartbeat Channel: Every 60 seconds, Antino uploads host telemetry to
/antino/heartbeats/{session_id}.json. Operator-supplied tools are pulled from/antino_uploads/, and stolen files are pushed to/antino_downloads/.
- Outlook Command Channel: Every 10 seconds, Antino queries the attacker's Outlook inbox for messages with subject
- In-Memory Sleep Masking (VEH): Antino hooks
SleepandVirtualAllocand registers a Vectored Exception Handler (VEH). Before sleeping, the payload memory page is modified toPAGE_READWRITEand encrypted in place. Upon wake, execution triggers an access violation caught by the VEH, which restores execution permissions and decrypts memory, defeating automated in-memory scanners. - Scripted Diagnostics Proxying: Antino executes commands and establishes persistence by activating COM class
CScriptedDiag({1F3D8AA5-9EBF-4EE4-85C2-EA40379AEDE8}). It loads the native Windows Program Compatibility Wizard (PCW) package and directssdiagnhost.exe -Embeddingto execute malicious PowerShell scripts (result.ps1), writing HKCU Run keys through Microsoft-signed diagnostic infrastructure.
MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)
| Tactic | Technique ID | Technique Name | Operational Context |
|---|---|---|---|
| Resource Development | T1583.001 | Acquire Infrastructure: Domains | Registering spoof domains (osc-cdn[.]com, microsoft-flash[.]com, wps-cn[.]com) |
| Initial Access | T1566.002 | Phishing: Spearphishing Link | Reconstructing Gmail attachment cards in HTML leading to Cloudflare Pages URLs |
| Execution | T1059.007 | Command and Scripting Interpreter: JavaScript | In-memory JScript decrypting and orchestrating .NET gadget deserialization |
| Execution | T1203 | Exploitation for Client Execution | BinaryFormatter AxHost+State and ActivitySurrogateSelector deserialization |
| Defense Evasion | T1574.002 | Hijack Execution Flow: DLL Side-Loading | Microsoft ADK binary GatherOsState.exe sideloading malicious slc.dll |
| Defense Evasion | T1027 | Obfuscated Files or Information | In-memory sleep masking with PAGE_READWRITE encryption and VEH dispatching |
| Defense Evasion | T1218 | System Binary Proxy Execution | Proxying PowerShell via Windows Scripted Diagnostics Host (sdiagnhost.exe) |
| Persistence | T1547.001 | Boot or Logon Autostart: Registry Run Keys | Adding HKCU Run keys via sdiagnhost.exe executing temporary result.ps1 scripts |
| Command and Control | T1102.002 | Web Service: Bidirectional Communication | Microsoft Graph API dead-drop communications via Outlook emails and OneDrive folders |
| Exfiltration | T1567.002 | Exfiltration Over Web Service: Cloud Storage | Exfiltrating sensitive host files to OneDrive /antino_downloads/ directory |
Threat Actor Profile & Campaign Attribution
Threat Cluster: UAT-11587 (China-Nexus Advanced Persistent Threat).
Attribution Assessment & Intelligence Markers:
- Confidence Level: High confidence China-nexus attribution based on the convergence of technical, linguistic, operational, and infrastructural artifacts.
- Preparation Environment Telemetry: Decoy document metadata recovered from Taiwan operations revealed internal document creation timestamps synchronized to UTC+8, the
zh-CNlanguage identifier, and the Simplified Chinese author string 未定义 ("undefined"). While UTC+8 spans several jurisdictions, pairing Simplified Chinese tags with +08:00 strongly indicates a mainland Chinese developer workstation targeting Traditional Chinese-speaking institutions. - Rust Build Ecosystem: Ten distinct Antino compiler builds recovered across campaigns contained embedded Cargo registry paths explicitly referencing `rsproxy.cn`, a mainland Chinese Rust package mirror utilized to accelerate crate dependencies behind national network boundaries.
- Overlaps with Known Threat Clusters: Symantec recently tracked overlapping Antino activity under the moniker Jewelbug, noting infrastructure intersections between cyber espionage and cryptocurrency fraud. Additionally, UAT-11587 leveraged Amazon CloudFront distribution
d32tpl7xt7175h[.]cloudfront[.]net, previously attributed by Arctic Wolf to Chinese state-sponsored threat group UNC6384 (distributors of PlugX).
Detection & SOC Mitigation Playbook
1. Patch & Workaround Guidance
- Restrict Windows Scripted Diagnostics Engine: Implement Application Control (AppLocker or Windows Defender Application Control [WDAC]) to restrict execution of
sdiagnhost.exeand block script execution fromC:\Windows\Temp\SDIAG_*directories. - Audit Microsoft Entra ID Application Permissions: Review all registered Entra ID multi-tenant and single-tenant applications for high-privilege Microsoft Graph API permissions granted under the OAuth 2.0 client-credentials flow, specifically
Mail.ReadWrite,Mail.Send,Files.ReadWrite, andFiles.ReadWrite.All. - Block ADK Sideloading Paths: Restrict
GatherOsState.exefrom executing outside its default installation path (C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\).
2. Network & Perimeter Defenses
- Enforce Strict DMARC Policy (`p=reject`): Upgrade organizational DMARC records from passive monitoring (
p=none) to strict enforcement (p=rejectorp=quarantine) to prevent attackers from abusing envelope-versus-header misalignment through external mail relays (e.g., Migadu). - Inspect Cloudflare Pages & R2 Outbound Connections: Inspect proxy logs for anomalous HTTPS requests to
*.pages.devand*.r2.devcontaining query strings with tracking parameters (e.g.,?m=or?track). - Deploy Snort / ClamAV Rules: Ensure intrusion prevention systems are updated with Snort rules
1:66880,1:66881, and1:66882covering Antino staging traffic.
3. Endpoint Detection & Hunting Query
title: UAT-11587 GatherOsState Sideloading and Scripted Diagnostics Abuse
id: 7c3d2e1f-4b5a-49e8-a6d1-9f0e8b2a3c4d
status: experimental
description: Detects GatherOsState.exe executing outside Windows Kits directory or sdiagnhost.exe executing PowerShell scripts from Temp directories indicative of Antino backdoor persistence
references:
- https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/
- https://cybernewsai.com/blog/china-uat-11587-antino-backdoor-espionage
author: CyberNewsAI Threat Intelligence
date: 2026/09/30
logsource:
category: process_creation
product: windows
detection:
selection_sideload:
Image|endswith: '\GatherOsState.exe'
filter_legit_adk:
Image|startswith: 'C:\Program Files (x86)\Windows Kits\'
selection_diagnostics:
ParentImage|endswith: '\sdiagnhost.exe'
Image|endswith: '\powershell.exe'
CommandLine|contains:
- '\Temp\SDIAG_'
- 'result.ps1'
selection_registry_run:
CommandLine|contains:
- 'Windows GatherOSStateKit'
- 'Antino'
condition: (selection_sideload and not filter_legit_adk) or selection_diagnostics or selection_registry_run
level: high
tags:
- attack.defense_evasion
- attack.t1574.002
- attack.t1218
- attack.persistence
- attack.t1547.001
falsepositives:
- Legitimate Windows Assessment and Deployment Kit testing by IT engineers in non-standard paths// Microsoft Sentinel / Defender XDR - Hunting for UAT-11587 Antino Infection Artifacts
// Identifies GatherOsState DLL sideloading, sdiagnhost proxying, and M365 staging directories
let SideloadEvents = DeviceProcessEvents
| where Timestamp >= ago(30d)
| where FileName =~ "GatherOsState.exe" and not(FolderPath startswith @"C:\Program Files (x86)\Windows Kits\")
| project Timestamp, DeviceName, ActionType="Abnormal GatherOsState Execution", FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, AccountName;
let DiagnosticAbuse = DeviceProcessEvents
| where Timestamp >= ago(30d)
| where InitiatingProcessFileName =~ "sdiagnhost.exe" and FileName =~ "powershell.exe"
| where ProcessCommandLine has_any ("SDIAG_", "result.ps1")
| project Timestamp, DeviceName, ActionType="Scripted Diagnostics PowerShell Proxy", FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, AccountName;
let StagingFiles = DeviceFileEvents
| where Timestamp >= ago(30d)
| where FolderPath has @"Windows GatherOSStateKit" or FileName in~ ("slc.dll", "OsGather.dat")
| project Timestamp, DeviceName, ActionType="Antino Staging File Event", FileName, FolderPath, ProcessCommandLine="", InitiatingProcessFileName, AccountName="";
union SideloadEvents, DiagnosticAbuse, StagingFiles
| sort by Timestamp descNetwork Indicators & Command-and-Control (C2)
| Indicator | Type | Context / Association |
|---|---|---|
| osc-cdn[.]com | Domain | Attacker-controlled spear-phishing SMTP envelope sender |
| oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev | Domain | Cloudflare Pages invariant campaign execution tracking beacon |
| d2nq35tel3ucuo[.]cloudfront[.]net | Domain | Amazon CloudFront staging endpoint for encrypted JScript/gadgets |
| pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev | Domain | Cloudflare R2 staging endpoint for TestAssembly & DLL bundle |
| pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev | Domain | Cloudflare R2 staging endpoint for secondary payloads |
| microsoft-flash[.]com | Domain | Standalone Antino fake-installer distribution domain |
| wps-cn[.]com | Domain | Standalone Antino fake-installer distribution domain |
| 103.27.110[.]220 | IPv4 Address | Historical hosting IP for Antino payload on wps-cn[.]com |
| graph.microsoft.com | Legitimate FQDN | Microsoft Graph API endpoint abused for Outlook & OneDrive dead-drop C2 |
| login.microsoftonline.com | Legitimate FQDN | Microsoft Entra ID OAuth 2.0 token acquisition endpoint |
File System & Hash Telemetry
| SHA-256 Hash | File / Role | Threat Context |
|---|---|---|
| 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff | slc.dll | Antino Gen 2 Rust backdoor payload (sideloaded) |
| e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 | slc.dll | Antino Gen 2 Rust backdoor variant |
| 1fadc90b61ce536abda78eb387a7f3d745f00c16775d3f762845ccc0fde567da | slc.dll | Antino Gen 1 Rust backdoor payload |
| 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd | Executable | Antino Gen 2 standalone fake installer |
| d753a615aedf8e58ffc75b2b7ebd320c0cbe6bcb5cbb885db749a2a85c55d3bf | TestAssembly.dll | .NET in-memory downloader (GUID b2b3adb0-...) |
| f0c1dc6d6daa4d010932c7818ed5f22929c182f58e5f495fabe2fb3cfc835b97 | JScript | Encrypted JScript orchestrator |
| e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 | HTA Stager | CSIS Indo-Pacific Forecast lure stager |
| f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 | HTA Stager | Taiwan Legislative tax ruling lure stager |
| e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf | HTA Stager | Philippine Bajo de Masinloc maritime lure stager |
osc-cdn.comoisadjfoinsiduhfnoisdnfosdnoifnsoid.pages.devd2nq35tel3ucuo.cloudfront.netpub-abfa7742e315485a98a5fafd6dbfb68e.r2.devpub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.devmicrosoft-flash.comwps-cn.com103.27.110.22009ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cffe2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb5301fadc90b61ce536abda78eb387a7f3d745f00c16775d3f762845ccc0fde567dad753a615aedf8e58ffc75b2b7ebd320c0cbe6bcb5cbb885db749a2a85c55d3bfAntinoUAT-11587
Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Light
“Because nation-state APTs strictly observe your weekend plans.”
Commemorate this cyber event. Printed on ultra-comfortable vintage garment-dyed 100% ring-spun cotton. Engineered for SOC war rooms, late-night incident bridges, and DEFCON.
// VERIFIED_SOURCES_&_REFERENCES
Watch Full Video Briefings on YouTube
Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.
Related Threat Intelligence
View Archive
Ex-Air Force Members Jailed Over Multimillion-Dollar BEC Fraud
Two former US Air Force members received 189 months in prison for a multi-million-dollar BEC fraud scheme. The ring spoofed vendors to divert wire payments.

Star Blizzard Deploys RedFlick in 100+ Org Cyber Espionage Wave
Russia's Star Blizzard targeted 100+ Western organizations using RedFlick fake event lures to deliver the CosmicPulse backdoor and DarkSword iOS exploit kit.

Japan's Keio Hit by Ransomware; Railway Resilient via Air-Gap
A ransomware attack crippled Keio Corporation's hotel reservations and retail payment systems, while strict OT air-gaps kept Tokyo's trains running on time.