Executive Summary
Government and policy organizations across eight Asian countries including Taiwan, India, Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria became targets of a sophisticated China-nexus espionage campaign orchestrated by threat actor UAT-11587 between September 2025 and June 2026. The attackers deployed a previously undocumented Rust-compiled backdoor called Antino, which uniquely leverages Microsoft 365 services including Outlook and OneDrive as command-and-control infrastructure instead of traditional C2 servers. The campaign utilized highly targeted spear-phishing emails with spoofed sender identities and fake Gmail attachment widgets to deliver multi-stage payloads, ultimately enabling host reconnaissance, shell execution, file transfer, and persistent access to compromised government systems. This incident demonstrates the evolving sophistication of nation-state actors who are increasingly abusing legitimate cloud services to blend malicious traffic with normal business communications, making detection significantly more challenging for traditional security controls.
Why This Matters Now
Nation-state actors are increasingly weaponizing trusted cloud platforms like Microsoft 365 for command-and-control, making their activities nearly indistinguishable from legitimate business traffic and bypassing traditional network security controls that focus on blocking suspicious external domains.
Attack Path Analysis
UAT-11587 initiated access through sophisticated spear-phishing emails with spoofed sender identities and fake Gmail attachment widgets, leading to HTA/WSF file execution. The threat actor established persistence through DLL sideloading and leveraged Windows Scripted Diagnostics framework for privilege escalation. Lateral movement occurred across multiple Asian government networks through reconnaissance and targeted expansion. Command and control was maintained exclusively through Microsoft 365 services using Outlook for commands and OneDrive for file transfers. Data exfiltration focused on government, policy, and diplomatic intelligence across 16 entities in 8 countries. The campaign achieved sustained espionage impact over multiple months with concentrated waves targeting critical government IT infrastructure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Spear-phishing campaign with spoofed sender identities and fake Gmail attachment widgets delivering HTA/WSF stagers via Cloudflare Pages URLs
MITRE ATT&CK® Techniques
Spearphishing Attachment
Spearphishing Link
Malicious File
DLL Side-Loading
Bidirectional Communication
Exfiltration to Cloud Storage
PowerShell
Process Injection
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Email Security Controls
Control ID: EM.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
NIS2 Directive – Risk Management Measures
Control ID: Article 21(2)(a)
Digital Operational Resilience Act (DORA) – ICT Risk Management Framework
Control ID: Article 8
PCI DSS 4.0 – Multi-layered Anti-malware Solutions
Control ID: 11.4.7
ISO 27001:2022 – Management of Vulnerabilities
Control ID: A.8.16
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Direct targeting by China-nexus UAT-11587 APT group using Antino backdoor via Microsoft 365, compromising government IT infrastructure across eight Asian countries through sophisticated spear-phishing campaigns.
Think Tanks
Policy research organizations targeted through tailored social engineering exploiting Microsoft Graph APIs, requiring enhanced egress security and zero trust segmentation to prevent lateral movement and data exfiltration.
Higher Education/Acadamia
Academic institutions in Taiwan's policy community specifically targeted since September 2025, vulnerable to encrypted C2 traffic through legitimate Microsoft 365 services bypassing traditional network security controls.
International Affairs
Diplomatic and foreign affairs entities across Asia targeted by espionage campaign using sophisticated lures focused on international security topics, exploiting trust relationships through spoofed sender identities.
Sources
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaignhttps://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.htmlVerified
- China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoorhttps://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/Verified
- China-Linked Jewelbug Uses XG Web for Cross-Platform Backdoor Operationshttps://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.htmlVerified
- China-Linked Hackers Exploit Windows Shortcut Vulnerabilityhttps://thehackernews.com/2025/10/china-linked-hackers-exploit-windows.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained UAT-11587's multi-stage espionage campaign by limiting lateral movement across government networks and restricting unauthorized egress through Microsoft 365 services. The segmented architecture would likely have reduced the attacker's blast radius from 16 entities across 8 countries to isolated workload compromises.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial workload compromise may have occurred through phishing, but segmented cloud fabric would likely have isolated the compromised endpoint from critical government resources and restricted the attacker's ability to enumerate cloud infrastructure across multiple networks.
Control: Zero Trust Segmentation
Mitigation: DLL sideloading and PowerShell execution may have succeeded locally, but zero trust segmentation would likely have constrained the elevated privileges to the immediate workload boundary, preventing privilege expansion across government network segments and cloud resources.
Control: East-West Traffic Security
Mitigation: Lateral movement between government entities would likely have been significantly constrained by east-west traffic controls, potentially limiting the campaign scope from 16 compromised entities to isolated network segments within individual organizations.
Control: Multicloud Visibility & Control
Mitigation: Command and control through Microsoft 365 services may have been established, but multicloud visibility would likely have detected abnormal communication patterns and constrained unauthorized service interactions across government cloud environments and SaaS platforms.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration through OneDrive would likely have been constrained by egress security policies, potentially limiting the volume and sensitivity of extracted government intelligence and blocking unauthorized file transfer operations to external cloud storage.
While some government intelligence may still have been compromised within individual network segments, the overall espionage impact would likely have been reduced from a multi-country diplomatic intelligence breach to isolated organizational exposures with limited cross-border policy intelligence access.
Impact at a Glance
Affected Business Functions
- Government Policy Development
- Diplomatic Communications
- National Security Operations
- Academic Research
Estimated downtime: 7 days
Estimated loss: $500,000
Confidential government policy documents, diplomatic communications, national security research, academic think tank analysis, and sensitive information related to Taiwan political and legislative matters across 16 entities in 8 Asian countries
Recommended Actions
Key Takeaways & Next Steps
- • Implement Egress Security & Policy Enforcement to detect and block unauthorized OneDrive/Outlook traffic patterns and prevent Microsoft 365 service abuse for C2 communications
- • Deploy East-West Traffic Security controls to detect lateral movement across government network segments and prevent expansion between compromised entities
- • Establish Zero Trust Segmentation with identity-based policies to limit privilege escalation through DLL sideloading and restrict access to critical government systems
- • Activate Multicloud Visibility & Control capabilities to monitor anomalous Microsoft 365 API interactions and detect suspicious automation patterns in cloud services
- • Enable Threat Detection & Anomaly Response systems to baseline normal Microsoft 365 usage and alert on covert communication channels through legitimate cloud services



