Cisco Talos published research on 2 October 2026 on a cluster it tracks as UAT-11587, which it assesses with high confidence to be China-nexus. Between September 2025 and July 2026 the group reached at least 16 institutional environments across eight Asian countries — Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria — and compromised roughly 350 endpoints.

The targets are governments, policy bodies and national security organisations. The tool is a Rust Windows backdoor called Antino. The interesting part is not what it can do, which is ordinary. It is where it sends its traffic.

The command channel is Microsoft

Antino communicates exclusively through the Microsoft Graph API, authenticating with an OAuth 2.0 client-credentials flow. It has two halves.

OneDrive is the dead drop. On first execution the implant writes a heartbeat JSON file into a path under its own name, and resends it every minute. Stolen files go into a separate downloads folder in the same account.

Outlook carries the conversation. The implant pulls commands from a mailbox folder the operator controls every ten seconds, matching messages by a subject line that embeds the session identifier, and writes its replies back the same way.

Ten seconds is the number to sit with. A dead drop is normally a slow channel — check in hourly, take what is there. At ten seconds the operator types a command and sees output before they have finished reading the last one. It behaves like a shell while looking like a mailbox.

Why this defeats network detection

Most intrusion detection at the network layer answers one question: is this host talking to somewhere it should not be? Reputation lists, newly registered domains, unusual destinations, traffic to a server in a country with no business relationship.

Antino never triggers any of it. Its traffic goes to Microsoft's Graph endpoint over TLS — the same destination used by Outlook, Teams, the file sync client and every other part of Microsoft 365. An organisation that uses Microsoft 365 cannot block it, cannot treat it as anomalous by destination, and cannot inspect it without breaking the rest of the platform.

The same thinking runs through the delivery. The final stage sideloads the backdoor by launching GatherOsState.exe, a legitimate Microsoft-signed binary from the Windows ADK, which loads a malicious DLL sitting beside it. The process that starts is signed by Microsoft. The network destination is Microsoft. The storage is Microsoft.

Nothing here is a vulnerability. It is a campaign built entirely out of the things a defender has already decided to trust.

The way in was still a phishing email

For all the sophistication downstream, the front door is familiar.

Talos describes spear-phishing with decoys tailored to geopolitical topics the recipient cares about, sent from addresses exploiting sender-domain misalignment to look like trusted organisations. One detail stands out: the attackers reproduced Gmail's attachment interface inside the message using base64-encoded images, so the recipient saw what looked like a native attachment and clicked through to a file hosted on Cloudflare Pages.

That is a picture of a button, not a button. The staging then runs through Cloudflare and Amazon CloudFront — more infrastructure nobody blocks.

Microsoft's own figures this week put user execution at 30 percent of observed initial access. This campaign is what that statistic looks like from the inside: five stages of staging, in-memory loading and signed-binary abuse, all of it waiting on one person clicking a picture of an attachment.

What Antino does once it is there

The capability list is deliberately unremarkable: command execution through cmd and PowerShell, host reconnaissance, file upload, download and listing, and in-memory shellcode loading. Persistence is a registry Run key. Evasion comes from hooking Sleep and VirtualAlloc, which is aimed at memory scanners rather than at the network.

An espionage implant does not need more than this. It needs to stay, read, and send — for eleven months, in this case, across 350 machines.

What to do

  • Treat Graph API traffic as data, not as background noise. Sign-in and audit logs for the tenant will show an application authenticating with client credentials, and that is the detection surface this campaign actually leaves.
  • Alert on the sideload, not the destination. A Microsoft-signed binary from the Windows ADK running outside its install path, loading a DLL from the same folder, is abnormal on an ordinary workstation.
  • Check for the registry Run persistence and for the folder structure Talos documents in the implant's OneDrive paths. Those are specific, and Talos published them.
  • Reconsider what your allow-list means. Cloudflare Pages, CloudFront and graph.microsoft.com are all permitted on the assumption that the destination implies the content. In this campaign the destination is the disguise.

What is not established

  • Who UAT-11587 works for. Talos assesses China-nexus with high confidence and intelligence gathering with moderate-to-high confidence, and names no sponsor.
  • Whose OneDrive and Outlook tenant was used, and whether those accounts were created by the actor or stolen.
  • What was taken from the 350 endpoints, and whether the 16 environments knew before the publication.
  • Whether the shared infrastructure overlaps Talos notes connect this to another known group. It puts low confidence on those links.