{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cloud-native-c2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["UAT-11587"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows (all versions)","Microsoft 365 (Outlook, OneDrive)"],"_cs_severities":["high"],"_cs_tags":["espionage","windows","cloud-native-c2","rust","spear-phishing"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eSince September 2025, the China-nexus threat actor UAT-11587 has engaged in sustained espionage targeting government, defense, and policy research organizations across Asia, including Taiwan, India, the Philippines, and Cambodia. The campaign is characterized by high-effort spear-phishing lures and a multi-stage infection chain that culminates in the deployment of \u0026quot;Antino,\u0026quot; a custom, Rust-compiled Windows backdoor. Antino is notable for its use of legitimate Microsoft 365 services, specifically Outlook and OneDrive, as an obfuscated command-and-control (C2) channel, effectively bypassing traditional network-perimeter-based detection by masquerading as standard cloud traffic. With over 350 compromised endpoints identified across eight countries, the actor demonstrates significant operational capacity for long-term intelligence gathering, leveraging Cloudflare infrastructure for payload staging and execution tracking.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial Access: The actor sends spear-phishing emails containing tailored decoy documents or links to cloud-hosted malicious content.\u003c/li\u003e\n\u003cli\u003eExecution: The target is lured into executing a malicious downloader or HTA file, often hosted on Cloudflare infrastructure, which initiates the infection sequence.\u003c/li\u003e\n\u003cli\u003eStaging: The initial downloader fetches secondary-stage payloads from cloud-hosted staging environments.\u003c/li\u003e\n\u003cli\u003ePayload Delivery: The custom Antino backdoor is dropped and executed on the victim host.\u003c/li\u003e\n\u003cli\u003ePersistence: Antino establishes persistence mechanisms on the Windows endpoint to maintain access across reboots.\u003c/li\u003e\n\u003cli\u003eReconnaissance: The malware performs host reconnaissance, collecting system information and user data.\u003c/li\u003e\n\u003cli\u003eC2 Communication: Antino communicates with Microsoft 365 (Outlook/OneDrive) to receive instructions and exfiltrate collected intelligence.\u003c/li\u003e\n\u003cli\u003eExfiltration: Data is uploaded to the actor-controlled OneDrive storage or sent via Outlook, completing the espionage cycle.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign has resulted in the compromise of approximately 350 endpoints across national security, diplomatic, legislative, and civil society sectors. Successful attacks allow the adversary to conduct deep reconnaissance, maintain persistent access, and exfiltrate sensitive policy and diplomatic intelligence. Given the focus on high-value public-sector targets, the breach of these systems represents a significant threat to regional stability and national security for the affected nations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eMonitor network traffic for unusual usage of Microsoft Graph APIs or excessive interaction with Microsoft 365 endpoints (Outlook/OneDrive) originating from servers or workstations that do not typically perform high volumes of office automation.\u003c/li\u003e\n\u003cli\u003eImplement strict controls on the execution of HTA files (HTML Applications) and block macros in untrusted documents via Group Policy.\u003c/li\u003e\n\u003cli\u003eDeploy EDR rules to monitor for Rust-compiled binaries executing from temporary directories or atypical user paths.\u003c/li\u003e\n\u003cli\u003eBlock connections to the identified CloudFront infrastructure domain \u003ccode\u003ed32tpl7xt7175h.cloudfront.net\u003c/code\u003e if detected in proxy or DNS logs.\u003c/li\u003e\n\u003cli\u003eConduct a hunt for the existence of unknown or unsigned Rust-compiled executables residing in common persistence locations like the Windows Startup folder or Run registry keys.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T18:31:58Z","date_published":"2026-09-30T10:18:45Z","id":"https://feed.craftedsignal.io/briefs/2026-09-china-uat11587/","summary":"China-nexus threat actor UAT-11587 is conducting long-term cyber espionage across Asia using the custom Rust-based Antino backdoor and Microsoft 365 services for command-and-control.","title":"China-nexus UAT-11587 Targets Asian Government Entities with Antino Backdoor","url":"https://feed.craftedsignal.io/briefs/2026-09-china-uat11587/"}],"language":"en","title":"CraftedSignal Threat Feed - Cloud-Native-C2","version":"https://jsonfeed.org/version/1.1"}