DEV Community

Mark0
Mark0

Posted on

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

Cisco Talos has identified a China-nexus threat actor, UAT-11587, targeting government, military, and policy organizations across Asia, including Taiwan, India, and the Philippines. The campaign utilizes a sophisticated five-stage infection chain initiated via spear-phishing emails that mimic legitimate services like Gmail attachment previews and spoof trusted sender domains to bypass email security filters.

The primary payload is Antino, a previously undocumented Rust-compiled backdoor capable of host reconnaissance, shell execution, and persistence. Notably, Antino leverages Microsoft 365 infrastructure for its command-and-control (C2) channel, using the Microsoft Graph API to interact with Outlook and OneDrive as dead-drops. This approach allows malicious traffic to blend seamlessly with legitimate enterprise application synchronization, complicating detection efforts.


Read Full Article

Top comments (0)