China-nexus threat actor UAT-11587 is targeting government and policy organizations across Asia and Syria with a newly discovered Rust-compiled backdoor named Antino. The campaign utilizes sophisticated spear-phishing tactics, including highly realistic fake Gmail attachment previews, to trick victims into downloading malicious HTA or WSF stagers. The actor has targeted at least 16 entities across multiple countries, focusing on diplomatic, maritime, and security themes.
Once executed, Antino leverages DLL sideloading via legitimate Microsoft binaries to evade detection and maintain persistence. For command-and-control (C2) operations, it uniquely abuses Microsoft 365 services, interacting with Outlook and OneDrive through the Microsoft Graph API. By using these legitimate cloud services as dead drops for command exchange and heartbeat signals, the malware effectively blends into standard enterprise network traffic.
Top comments (0)