Skip to main content
Emerging ThreatsMalware & Ransomware

China-Nexus Espionage Campaign Exploits Outlook, OneDrive

Laptop on a desk in a neutral Asian-style building setting.

"The Antino backdoor abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components." That technical detail points to a larger, targeted espionage campaign that has used Microsoft Outlook and OneDrive as covert command-and-control channels.

UAT-11587: scope and timeline of the campaign

Cisco Talos tracks the activity cluster as UAT-11587. First detected in September 2025, the campaign began against Taiwan's academic, think-tank, and civil-society policy community and expanded to touch 16 entities across eight Asian countries, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. Evidence also indicates that organizations in Syria were targeted around May 2026. Attack activity spiked between March and early June 2026, with a concentrated wave on June 8–9, 2026, that struck dozens of systems associated with government IT infrastructure.

Antino: a Rust backdoor that hides in plain sight using Microsoft 365

Cisco Talos identified the central implant as Antino, a Rust-compiled Windows backdoor. According to security researcher Ashley Shen, Antino "supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence." Rather than using a dedicated internet-based command-and-control server, Antino's native channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.

Specifically, Antino fetches commands from the actor's Outlook mailbox every 10 seconds by searching for messages with the subject prefix "command_req_[session_id]." OneDrive is used for heartbeat signals and file transfer. The implant can list running processes, enumerate directories, run PowerShell scripts and shellcode, and launch operator-supplied programs and commands using cmd.exe.

The intrusion chain: HTA/WSF stagers, .NET deserialization, and DLL sideloading

Talos mapped a five-stage attack chain that begins with a Cloudflare Pages URL embedded in a spear-phishing email. That URL delivers an HTA or WSF stager which retrieves a JavaScript downloader and decryptor. The next stage leverages a .NET deserialization chain to load a component named TestAssembly.dll. Talos reports TestAssembly.dll performs three actions: it downloads and opens the lure document for the victim, downloads a decoy Calculator executable, and downloads and launches the Antino backdoor.

The implant is delivered as "slc.dll" and is launched via DLL sideloading using a legitimate Microsoft-signed binary, GatherOsState.exe. Once resident, Antino communicates with Microsoft 365 through Microsoft Graph to perform its C2 exchanges using Outlook and OneDrive.

Tradecraft: social engineering, mimicry, and supply-chain signals

The spear-phishing messages used multiple social-engineering techniques to increase credibility. The actor spoofed sender identities trusted by recipients, deliberately attempting to bypass SPF and DMARC checks and ensure delivery to inboxes. In one notable tactic, the actor closely replicated Gmail's native attachment preview widget inside the email HTML body: four inline PNG images embedded as Base64-encoded MIME parts formed a fake attachment card wrapped in an anchor tag that pointed to an attacker-controlled Cloudflare Pages URL. When opened in a browser, Gmail's renderer displayed an attacker-controlled HTML that was visually indistinguishable from a legitimate Gmail attachment preview.

Talos also flagged supply-chain and tooling artifacts that bolster the actor assessment: nearly a dozen Antino build outputs contained Cargo registry paths referencing rsproxy[.]cn, a high-speed mirror for crates.io serving mainland China. A JavaScript downloader tied to UAT-11587 referenced a CloudFront domain — d32tpl7xt7175h.cloudfront[.]net — previously flagged by Arctic Wolf in connection with a separate campaign conducted by UNC6384.

Attribution signals and the Jewelbug comparison

Talos assessed the adversary as China-nexus with high confidence, citing zh-CN language and Simplified Chinese metadata in lure documents and a UTC+08:00 time zone in a spear-phishing message header. Talos noted tactical overlap with a cluster it calls Jewelbug — itself described by Broadcom-owned Symantec and Carbon Black in August 2026 as a China-based hackers-for-hire group that conducts espionage and a separate cryptocurrency fraud business. However, Cisco Talos said its investigation did not uncover a connection between UAT-11587's espionage activity and Jewelbug's financially motivated operations, and therefore designated UAT-11587 as a separate activity set.

What this means for technologists, policymakers, and diplomats

  • Technologists and security teams: Expect active exploitation of trusted cloud services for covert C2. Talos notes Antino uses Microsoft Graph to interact with Outlook and OneDrive and abuses the Windows Scripted Diagnostics framework to run PowerShell through legitimate components — behaviors that can obscure attribution and complicate detection but will still leave PowerShell, file-creation, or Registry telemetry.
  • Policymakers and diplomats: The lures and targets — including Taiwanese political, legislative, civil-defense, and policy-research subjects and regional maritime, diplomatic, and security themes — indicate an intelligence collection focus. The campaign's geographic spread to Syria and the concentrated June 8–9, 2026 wave suggest operational campaigns tied to regional priorities and timing.
  • Affected government IT leaders: The attack chain demonstrates a blend of tailored reconnaissance, sender spoofing to bypass SPF/DMARC, and convincing visual mimicry of Gmail, indicating defenders should assume targeted reconnaissance precedes tailored lures.

UAT-11587's use of legitimate cloud services and signed binaries underscores a simple, persistent fact: adversaries that stitch together authentic tooling, convincing social engineering, and commodity cloud platforms can build resilient espionage channels that are hard to spot. Talos's findings leave open whether the tooling overlaps with other known clusters represent shared tradecraft, operational collaboration, or convergent evolution — but they do confirm a sophisticated, regionally focused campaign that relied on Microsoft 365 as its covert nervous system.

Original report