What Talos found
A targeted phishing chain ends in cloud-blended command and control
Cisco Talos reports that UAT-11587 targeted government, policy, and national-security-adjacent organisations across Asia. Talos assesses with high confidence that the activity is China-nexus. One recurring payload, a Rust-compiled Windows backdoor called Antino, uses Microsoft Graph with Outlook and OneDrive rather than a dedicated command server.
Trusted SaaS traffic is not an identity of safety
Delivery chain
Join email, endpoint, cloud, and identity evidence
| Stage | Reported behavior | Defender evidence |
|---|---|---|
| Initial access | Tailored spear phishing with a cloned Gmail attachment widget. | Message headers, sender alignment, URL extraction, recipient-specific tracking parameters. |
| Execution | HTA or WSF stagers invoke mshta.exe and load subsequent code. | Process tree, script telemetry, downloaded content, proxy and DNS records. |
| Payload | A signed GatherOsState.exe is used to sideload a malicious slc.dll. | File provenance, signer data, adjacent DLLs, endpoint execution and load events. |
| C2 | Microsoft Graph accesses Outlook and OneDrive as dead-drop channels. | Entra application records, OAuth use, Graph audit logs, mailbox and OneDrive activity. |
First response
Contain carefully and preserve the cloud context
- 1
Scope the affected identity and endpoint together. Preserve the host, signed-in user, relevant Entra application details, token and consent history, mailbox audit events, OneDrive audit events, and endpoint process telemetry before revoking or rebuilding.
- 2
Review application and consent records. Identify unfamiliar application registrations, service principals, credentials, grants, and client-credentials flows. Confirm the owner, purpose, allowed permissions, and the accounts or resources each can reach.
- 3
Hunt the reported execution sequence. Look for phishing downloads followed by mshta.exe or Windows Script Host, in-memory .NET activity, and GatherOsState.exe executing beside an unexpected slc.dll.
- 4
Contain with evidence in hand. Disable or restrict malicious identities and applications, revoke sessions and credentials as appropriate, isolate affected hosts, and preserve a timeline before deleting cloud objects that may explain the intrusion.
- 5
Recover the trust boundary. Rotate affected credentials, remove unauthorised registrations and grants, validate mail controls and endpoint policy, and test that required Microsoft 365 integrations still work under least privilege.
Hunt
Use the reported markers as pivots, not a complete detection rule
- Review Graph API and Entra audit data for unusual client-credentials use, unfamiliar application owners, and access patterns tied to a small set of devices or service identities.
- Search OneDrive activity for unusual paths resembling
/antino/heartbeats/,/antino_downloads/, or/antino_uploads/, while treating those names as research pivots rather than universal indicators. - Review Outlook activity for message subjects beginning
command_req_orcommand_res_and correlate any hits with endpoint and application activity. - Investigate fake attachment interfaces and protocol-relative URLs in inbound mail; enforce sender alignment and make out-of-band verification easy for high-risk teams.
Defender note
Cloud controls must see the purpose of access
Antino's design is a reminder that application identity is a security boundary. Network allow lists for major SaaS platforms may still be necessary, but they cannot establish that an Entra application, mailbox, or file path is legitimate. Keep endpoint, mail, identity, and SaaS audit data connected well enough to test the purpose behind trusted traffic.