{"success":true,"data":{"threats":[{"id":"575eea5b-c4fb-4518-9159-e0d913066c60","slug":"talos-uat-11985-ai-assisted-event-lures-delivering-real-time-google-89efa3d6","externalId":"6ac65ab5b0849f0001774482","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing","description":"Cisco Talos identified an advanced persistent threat (APT) spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions to establish credibility.&#xa0;The phishing emails exhibited highly consistent structure, rhetoric, and personalization patterns, suggesting the threat actor likely used AI-assisted content generation to rapidly customize invitation lures for different targets while maintaining a common social engineering framework.&#xa0;Beyond traditional email phishing, the actor incorporated QR code phishing (quishing) techniques by modifying legitimate event posters with malicious QR codes, expanding the attack surface beyond email recipients to secondary victims who may encounter printed materials.&#xa0;The campaign deployed an advanced adversary-in-the-middle (AitM) phishing framework that impersonated Google authentication pages and utilized a hybrid HTTP and WebSocket architecture to synchronize authentication workflows in real time, enabling the interception of credentials and multi-factor authentication (MFA) challenges.&#xa0;After technical analysis of the phishing kit, Talos assesses with moderate confidence that the user interface was originally developed in Simplified Chinese and later adapted for Traditional Chinese and English. The localization architecture, Simplified Chinese default language branch, and mainland-Chinese lexical usage collectively suggest a developer whose primary working language is Simplified Chinese.In mid-2026, Talos observed an APT spear-phishing campaign targeting Taiwan-based research organizations. The threat actor appeared to reuse legitimate or plausible public event information, then embedded a hyperlink to actor-controlled infrastructure, while the displayed URL appeared benign. Several invitation emails exhibited nearly identical syntactic structures despite discussing different geopolitical topics, suggesting the content was generated from a reusable prompt template rather than independently authored. While Talos cannot conclusively determine whether the emails were fully generated by a large language model (LLM), the campaign demonstrates strong evidence of AI-assisted content production and personalization.&#xa0; Spear-phishing mail&#xa0;Based on the phishing emails we observed, the threat actor impersonated legitimate institutions in Taiwan such as Taiwan European Union Centre, NCCU Institute of International Relations, and Taiwan Research Institute. Below is a deep analysis of the mail contents. Figure 1. Impersonated Taiwan European Union Centre event.Figure 2. Impersonated NCCU Institute of International Relations event.Figure 3. Impersonated Taiwan Research Institute event.An email recipient contacted the organizations concerned to verify the purported senders. However, none of the organizations could confirm that the three senders were employees or representatives of the institutions named in the emails. This suggests that the threat actor fabricated the sender identities while using legitimate organizational names and publicly available event information as cover. All three emails follow a highly consistent, three-part structure, indicating the use of a common template. The opening section provides a polished (but overly elaborate) description of the geopolitical or policy context. It relies heavily on grandiose yet vague expressions such as &#x201c;the global strategic landscape,&#x201d; &#x201c;reshaping the great-power order,&#x201d; &#x201c;three-dimensional analysis,&#x201d; &#x201c;forward looking and in-depth analysis,&#x201d; and &#x201c;high intensity professional dialogue&#x201d; to create an impression of academic authority and subject matter expertise. Although the language is generally fluent, the excessive use of policy jargon and abstract strategic terminology makes the content appear formulaic. The second section is customized for the recipient and uses targeted flattery to encourage engagement. Similar phrases including &#x201c;admiration,&#x201d; &#x201c;authoritative perspective,&#x201d; &#x201c;highly perceptive,&#x201d; and &#x201c;key practical dimensions&#x201d; appear across the three messages. These compliments are broadly applicable and contain few verifiable details about the recipient&#x2019;s actual work, suggesting that the actor personalized a reusable template using publicly available professional information. References to exclusive participation, reserved VIP seating, or the recipient&#x2019;s supposedly unique expertise further exploit professional recognition and status to reduce suspicion. The final section presents event logistics, including the topic, date, venue, and registration instructions. Although much of this information appears to have been copied from legitimate institutional websites or public event announcements, its accuracy does not validate the email or the sender. Instead, the actor appears to use authentic event details as a form of legitimacy laundering. The registration links embedded in the emails do not direct recipients to the legitimate event registration pages they seem to represent. For example, one hyperlink displays a legitimate-looking Google Forms URL, while its underlying href redirects the recipient to a deceptive phishing site hosted on a third-party platform. This mismatch between the visible link text and the actual destination demonstrates a deliberate attempt to conceal the phishing infrastructure and exploit the recipient&#x2019;s trust in a familiar service. Figure 4. Hyperlink phishing destination.Taken together, the reuse of an almost-identical narrative structure, rhetorical style, personalized flattery, institutional impersonation, and deceptive registration mechanism strongly suggests a coordinated and carefully targeted spear-phishing campaign rather than three independent invitations. The messages also exhibit characteristics consistent with AI-assisted content generation such as grammatically fluent but formulaic prose, excessive use of grandiose and abstract policy terminology, interchangeable praise, repetitive sentence patterns, and rapid customization for different recipients, institutions, and geopolitical topics. Although these linguistic indicators alone cannot conclusively prove the use of generative AI, their consistency across all three emails suggests that the threat actor likely used an AI-assisted template to produce and personalize the phishing lures at scale. The legitimate event details and visible Google Forms URLs were then combined with disguised hyperlinks leading to actor-controlled phishing pages, making the emails appear credible while concealing their actual destination.&#xa0; Quishing in the poster&#xa0;We also observed the threat actor attaching event posters to several phishing emails. While the poster designs were scraped from legitimate websites, the embedded QR codes were maliciously altered. This modification indicates a calculated physical world attack vector. The actor may have anticipated that recipients might print and display these posters on office bulletin boards, thereby tricking other individuals into scanning the malicious QR code to register for the event. By doing so, the threat actor expands their attack vector beyond traditional email phishing to include quishing (QR code phishing), and broadens their reach within the targeted entities. Figure 5. Legitimate poster (left) and modified poster (right).Phishing kit used by UAT-11985&#xa0;Phishing page&#x2019;s impersonation&#xa0;These three phishing email attacks use the same tactics, techniques, and procedures (TTPs) which include a phishing page impersonating a legitimate Google Form and appearing visually identical to the authentic service. However, aligned with the threat actor&apos;s primary objective of credential theft, the malicious form forcibly redirects the user to a spoofed Google login page. Figure 6. Form forcibly redirects to a spoofed Google login page.Talos observed that the spoofed Google login panels only support Simplified Chinese (zh-CN), Traditional Chinese (zh-TW), and English locales, with region detection based on the victim&apos;s browser &#x201c;navigator.languages&#x201d;, strongly suggesting targeting of Chinese-speaking users. Figure 7. Spoofed Google login panels.We also observed that this phishing page revealed a hidden HTML <section> designed to simulate a successful Google authentication event. Within this structure, the threat actor embedded an iframe (ID: google-success-frame) configured to load a locally hosted asset (/google-login-assets/operation-success.html). Notably, the iframe includes the sandbox=\"allow-scripts\" attribute. We will discuss JavaScript in the next section. Figure 8. Google success page.&#xa0;Attack summary&#xa0;&#xa0;The attack chain initiates when a victim clicks a malicious URL delivered via a phishing email. Upon access, the victim is presented with a pixel-perfect replica of the Google sign-in page, which covertly hosts an obfuscated JavaScript payload. Operating as an adversary in the middle (AitM), the threat actor positions their infrastructure between the victim&apos;s browser and legitimate Google authentication servers. This allows them to seamlessly forward credentials and dynamically control the victim&apos;s user interface step-by-step via a persistent WebSocket connection. Figure 9. Attack chain.To evade detection and complicate analysis, the malicious JavaScript is embedded at the end of the HTML document and relies on advanced string rotation obfuscation. The script leverages a large, static array of Base64 encoded strings coupled with control flow obfuscation. By utilizing a while(!![]) { push/shift } shuffle loop mechanism, the array rotation is resolved dynamically at runtime, effectively thwarting automated static deobfuscation tools. Figure 10. Obfuscation of malicious JavaScript.Talos&#x2019; analysis of the phishing kit&apos;s client-side JavaScript indicates, with moderate confidence, that the user interface localization was authored by a native Simplified Chinese speaker. The strongest indicator is the kit&apos;s localization architecture:&#xa0;&#xa0; The base translation object (T) is written entirely in Simplified Chinese and is directly assigned as the zh-CN locale, while the Traditional Chinese (zh-TW) and English (en) locales are derived from it at runtime via an override or merge function (v(T, {...})).&#xa0;&#xa0;This structure demonstrates that the interface was originally composed in Simplified Chinese and subsequently translated into Traditional Chinese and English, consistent with Simplified Chinese being the developer&apos;s primary working language.This assessment is reinforced by lexical choices characteristic of mainland Chinese usage rather than Taiwanese, Hong Kong, or Southeast Asian conventions. For example, the text uses Simplified Chinese forms such as &#x201c;&#x8d26;&#x53f7;&#x201d; for &#x201c;account,&#x201d; whereas Traditional Chinese environments would more commonly use &#x201c;&#x5e33;&#x865f;&#x201d; or related variants. Similarly, terms such as &#x201c;&#x8ba1;&#x7b97;&#x673a;&#x201d; for &#x201c;computer,&#x201d; &#x201c;&#x90ae;&#x7bb1;&#x201d; for &#x201c;email/mailbox,&#x201d; &#x201c;&#x65e0;&#x75d5;&#x6d4f;&#x89c8;&#x7a97;&#x53e3;&#x201d; for &#x201c;incognito browsing window,&#x201d; and &#x201c;&#x8bbf;&#x5ba2;&#x6a21;&#x5f0f;&#x201d; for &#x201c;guest mode&#x201d; reflect terminology commonly seen in mainland-oriented Simplified Chinese software localization. In Taiwanese or Hong Kong contexts, these concepts are typically rendered with Traditional Chinese characters and often different localized wording, such as &#x201c;&#x96fb;&#x8166;,&#x201d; &#x201c;&#x96fb;&#x5b50;&#x90f5;&#x4ef6;/&#x4fe1;&#x7bb1;,&#x201d; or &#x201c;&#x7121;&#x75d5;&#x5f0f;&#x8996;&#x7a97;.&#x201d; This linguistic pattern is further supported by the ternary-fallback ordering throughout the code, which consistently places Simplified Chinese as the default branch.Figure 11. Language and developer assessment.Operator-driven phishing page&#xa0;Following the deobfuscation and analysis of these JavaScript payloads, Talos identified an advanced, real-time AitM phishing kit targeting Google accounts. Unlike fully automated phishing kits, this framework appears optimized for operator-driven authentication orchestration. This kit impersonates the Google sign-in interface across three locales (zh-CN, zh-TW, en) and employs a dual-channel architecture including HTTP POST and WebSocket to synchronize Google&apos;s authentication state in real time. This mechanism effectively bypasses multi-factor authentication (MFA) to harvest complete, authenticated session tokens. The threat actor deliberately employs a split communication channel architecture to optimize both data exfiltration and real-time command and control (C2) efficiency. For the outbound data exfiltration, the threat actor utilized HTTP POST for stateless, event-driven data transmission. The phishing page actively pushes captured data to the C2 server, including initial browser fingerprints, credential and challenge submissions during user interaction, and periodic heartbeat polls to maintain synchronization. Each call completes independently. Figure 12. Outbound data exfiltration with HTTP.The threat actor uses WebSocket to provide a low-latency, persistent connection. The C2 server streams real-time instructions to the phishing page via this channel, dictating exactly which MFA challenge screen to render. Cisco Talos has also recently published a report on a different phishing campaign where similar WebSocket techniques were observed in a phishing kit used by a Chinese-speaking actor. However, the strategies employed by that phishing kit differ from those in this case. Figure 13. Inbound command and control with WebSocket.The following diagram illustrates the real-time AitM relay architecture. Figure 14. UAT-11985 operating diagram.At the beginning phase, the threat actor collects device and browser information, including the locale, user agent, screen dimensions, and mobile-device status. This data is sent to the actor&#x2019;s HTTP C2 server through a google_login_start request. After the server creates a session, the JavaScript establishes a WebSocket connection with the actor&#x2019;s C2 infrastructure and receives a snapshot containing the current session state. Figure 15. Mobile device status check.The victim enters an email address or phone number into the fake Google login page. The phishing page sends the identifier to the actor&#x2019;s HTTP C2 server using the google_input_identifier event. The actor&#x2019;s server then relays the identifier to the real Google authentication service to verify whether the account exists and determines whether a passkey-based flow is enabled. Based on Google&#x2019;s response, the actor instructs the phishing page through WebSocket state updates to display either the password-entry page or a passkey prompt. Figure 16. Authentication challenge function.&#xa0;When the victim submits a password, the phishing page sends the password, account identifier, and browser user-agent information to the actor&#x2019;s HTTP C2 server through a google_login_check request. The actor&#x2019;s server forwards the credentials to the real Google authentication service. If the credentials are accepted and Google requires additional authentication, the server returns the MFA challenge type and layout. The actor then advances the victim&#x2019;s interface to the appropriate MFA step through a WebSocket update. Figure 17. google_login_check request.&#xa0;By deliberately splitting one-shot uploads with POST requests from low-latency state updates with WebSocket connection, the threat actor has engineered a seamless credential-harvesting relay. This allows the threat actor to mirror Google&apos;s dynamic authentication state in real time, ultimately achieving full account takeover without raising the victim&apos;s suspicion. Coverage&#xa0;&#xa0;The following ClamAV signatures detect and block this threat: &#xa0; Html.Phishing.UAT11985-10060614-0&#xa0;The following SNORT&#xae; rules (SIDs) detect and block this threat:&#xa0; &#xa0; Snort2: 1:67198Snort3: 7:31Indicators of compromise (IOCs)&#xa0;&#xa0;The IOCs can be found in our GitHub repository here.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-spotlight","ai","apt","cisco-talos-network-intrusion-prevention","cisco-talos-email-threat-prevention","cisco-talos-web-filtering","geo:inferred"],"relatedCves":[],"titleFingerprint":"11985-aitm-assisted-delivering-event-google-lures-phishing-real-time-uat","countryCodes":["CN","HK","TW"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/uat-11985/","type":"report","title":"Cisco Talos: UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T10:01:06.000Z","addedAt":"2026-10-08T10:41:26.604Z","updatedAt":"2026-10-08T10:41:26.604Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"b03974dc-16e5-453f-8f31-6bf2028276b9","slug":"talos-china-nexus-uat-11587-targets-government-and-policy-94d4e2d7","externalId":"6ab6d674db2bd20001a36150","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor","description":"Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as &#x201c;Antino&#x201d; in developer artifacts.&#xa0;Talos first observed UAT-11587 activity in September 2025.&#xa0;By July 2026, Talos had identified at least 16 affected or targeted institutional environments across eight Asian countries.&#xa0;Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence. Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.&#xa0;Talos identified a recurring delivery branch that began with spear-phishing emails and tailored decoy documents, followed by a five-stage infection chain. The actor relied heavily on Cloudflare infrastructure for delivery, execution tracking, and payload staging.&#xa0;Based on the development, preparation-environment, and targeting indicators detailed in this report, Talos assesses with high confidence that UAT-11587 is China-nexus.Overview&#xa0;Talos first identified UAT-11587&#x2019;s campaign while investigating a spear-phishing campaign directed at Taiwan&apos;s academic, think tank, and civil society policy community in March 2026. The message recreated Gmail&apos;s attachment interface and directed the target into a cloud-hosted, multi-stage infection chain.&#xa0; Across this activity, our researchers assessed that the actor used several delivery methods, loader families, and post-compromise tools. One recurring final-stage payload was a custom Rust backdoor that Talos tracks as Antino. Antino communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, rather than depending on a conspicuous dedicated command server.&#xa0; Further investigation showed that the activity extended beyond the initial Taiwan operation. Talos subsequently identified confirmed or probable affected government and security environments across multiple Asian countries, alongside additional regional targeting supported by lure content.&#xa0;&#xa0; While this report was being prepared, Symantec published research on an activity set it tracks as Jewelbug. Talos identified overlaps between UAT-11587 and the Antino-related espionage activity attributed to Jewelbug. Although Symantec reported that Jewelbug conducted both espionage and cryptocurrency fraud, it assessed that &#x201c;the SEO business supplied access, delivery and infrastructure into the espionage operation, rather than that one person performed both roles.&#x201d; Talos could not independently verify a connection between the espionage campaign and Jewelbug&#x2019;s financially motivated activity. We therefore track UAT-11587 as a separate activity set.&#xa0; Who is UAT-11587?&#xa0;Talos assesses with high confidence that UAT-11587 is a China-nexus actor, based on the totality of corroborating technical and operational evidence, rather than any single indicator. The indicators discussed below are selected examples of the broader evidence supporting this assessment.&#xa0; Evidence supporting the attribution assessment&#xa0;Decoy document metadata provides several preparation-environment clues. A Taiwan-focused decoy contains the zh-CN language tag, the Simplified Chinese author value &#x672a;&#x5b9a;&#x4e49; (&#x201c;undefined&#x201d;), and an explicit +08:00 creation timestamp. Both recovered spear-phishing messages also contain +08:00 date headers. UTC+8 alone is not geographically distinctive because it is used across mainland China, Taiwan, Hong Kong, Singapore, and other locations. However, the combination of the +08:00 offset, the zh-CN language tag and Simplified Chinese metadata is more consistent with a mainland Chinese environment than with Taiwan or Hong Kong, where Traditional Chinese predominates.&#xa0; Figure 1. Decoy metadata.&#xa0;The campaign&#x2019;s lure theme and targeting provide additional contextual support. Its lures and observed targets include Taiwanese political, legislative, civil defense, and policy research subjects, together with regional government, maritime, diplomatic, and security themes. This collection focus is consistent with China-nexus actor interests.&#xa0;&#xa0; Another supporting indicator appears in Antino&#x2019;s development artifacts. Ten distinct Antino build outputs contain Cargo registry paths referencing rsproxy.cn, a Rust package mirror intended to improve dependency downloads within mainland China. The service&#x2019;s public accessibility does not reveal the developer&#x2019;s location, but its repeated use suggests reliance on a China-focused Rust mirror.&#xa0; During our investigation, Talos also identified a JavaScript downloader associated with UAT-11587 that referenced &#x201c;d32tpl7xt7175h[.]cloudfront[.]net&#x201d;, the same CloudFront distribution previously reported by Arctic Wolf in China-nexus UNC6384 delivery activity. This shared infrastructure suggests possible delivery-layer overlap. However, because cloud infrastructure can be reused and the campaigns employed different core malware and command-and-control (C2) architectures, Talos assesses this relationship with low confidence and continues to track UAT-11587 as a separate activity cluster.&#xa0;&#xa0; Victimology&#xa0;UAT-11587 primarily targeted public-sector and national-security-adjacent organizations across Asia. By July 2026, Talos had identified at least 10 confirmed and five probable affected institutional environments, plus one additional intended target. Our investigation reveals approximately 350 compromised endpoints across eight countries.&#xa0; &#xa0;The affected or targeted sectors included:&#xa0; Defense, military, and national security&#xa0;Executive government and central public administration&#xa0;Foreign affairs and diplomatic services&#xa0;Justice, law enforcement, border security, and interior security&#xa0;Legislative and parliamentary institutions&#xa0;Government IT and shared e-government services&#xa0;Think tanks, universities, and research institutions&#xa0;Civil society, human rights, and public policy organizations&#xa0;&#xa0;Based on the available evidence, Talos assesses with moderate-to-high confidence that the campaign targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria.&#xa0; Figure 2. Victimology mapBased on its sustained targeting of government and national security-adjacent organizations, tailored political and diplomatic lures, and capabilities supporting persistent access and information collection, Talos assesses with moderate confidence that UAT-11587 is conducting intelligence gathering operation. &#xa0; Campaign timeline&#xa0;Talos observed UAT-11587 activity from September 2025 through July 2026. The earliest reviewed activity, from September through November 2025, used Philippines-themed lures and direct email attachment delivery. In January 2026, the actor conducted two additional Philippines-focused HTML application (HTA) campaigns and began using a broader set of policy and geopolitical lures alongside a standalone fake installer delivery branch. Activity accelerated between March and early June, with closely timed operations involving the Philippines and Taiwan, followed by activity affecting or targeting environments in Cambodia, Myanmar, Syria, Pakistan, and Thailand. The largest concentrated wave occurred on June 8 and 9, when Talos identified around 57 newly observed endpoints associated with India.&#xa0; Figure 3. Timeline of UAT-11587 campaign activity.Spear-phishing delivery and sender spoofing&#xa0;UAT-11587, like many targeted intrusion sets, relies on spear-phishing emails to deliver its infection chain. The social engineering themes used in these emails suggest the threat actor possessed detailed prior knowledge of their target organizations. This targeting precision is particularly apparent in the Taiwan campaigns, where lure content was carefully aligned with the operational and institutional context of each target.&#xa0; Abusing sender-domain misalignment to spoof trusted senders&#xa0;To make its spear-phishing emails appear more credible, UAT-11587 spoofed sender identities trusted by the intended recipients. The actor exploited the distinction between the SMTP envelope sender and the visible From header. Messages were sent through Migadu using the attacker-controlled &#x201c;osc-cdn[.]com&#x201d; domain as the RFC5321 envelope sender, while the RFC5322 From header displayed the identity of the organization being impersonated.&#xa0; &#xa0;SPF passed because Migadu&#x2019;s sending infrastructure was authorized to send email on behalf of &#x201c;osc-cdn[.]com&#x201d;. However, this result authenticated only the envelope-sender domain, not the sender displayed to the recipient. DMARC detected that the envelope and visible sender domains were not aligned and returned a failure. In the reviewed message, the displayed domain used a non-enforcing p=none policy, which requested monitoring rather than quarantine or rejection. The receiving provider therefore accepted the message, allowing the spoofed email to be successfully delivered to the recipient&#x2019;s inbox despite the DMARC failure.&#xa0;&#xa0; Figure 4. The spoofed email passed SPF.&#xa0;Gmail attachment widget cloning&#xa0;Another social engineering technique used for initial access in this campaign was the closely replicated reconstruction of Gmail&#x2019;s native attachment preview widget inside the email HTML body. The actor replicated the styling of Gmail&#x2019;s attachment card using four inline PNG images embedded as Base64-encoded MIME parts. The entire attachment card was wrapped in an anchor tag pointing to an attacker-controlled URL. These links use Cloudflare Pages URLs with the pattern shown below. The ?m= parameter carries a target identifier and therefore permits per-recipient logging at the delivery service //my-<project>.pages.dev/File_download?m=<target-identifier>. The actor used a protocol-relative URL beginning with //, which may be overlooked by security tools that extract only fully qualified HTTP or HTTPS URLs.&#xa0; When a Gmail user opens the email in a browser, Gmail&#x2019;s renderer faithfully displays the attacker-controlled HTML, producing a fake attachment widget that is visually indistinguishable from a legitimate Gmail attachment preview.&#xa0; Figure 5. Spear-phishing email sample.Figure 6. HTML code in the email with link to download malware.Tailored lures and decoy documents&#xa0;Our analysis recovered three decoy documents during separate UAT-11587 operations. The first decoy described a workshop focused on the &#x201c;Taiwan Information Warfare.&#x201d; The document referenced a 2025 TikTok study and discussed perceived public knowledge gaps concerning cross-strait issues and information manipulation.&#xa0;&#xa0; Figure 7. Decoy document recovered from Taiwan-targeting campaign.&#xa0;The second decoy, titled &#x201c;&#x7acb;&#x6cd5;&#x59d4;&#x54e1;&#x884c;&#x4f7f;&#x8077;&#x52d9;&#x652f;&#x9818;&#x4e4b;&#x5404;&#x9805;&#x8cbb;&#x7528;&#x5fb5;&#x514d;&#x7a05;&#x539f;&#x5247;&#x201d; (&#x201c;Principles governing the taxation of expenses received by legislators in performing their duties&#x201d;), used a narrower administrative pretext. It describes the income tax treatment of legislators&#x2019; remuneration, overseas travel, and expenses incurred while performing legislative duties. The document exactly reproduces a public Taiwan Ministry of Finance ruling to make the decoy appear credible. Its subject strongly suggests that it was prepared for members of Taiwan&apos;s public sector.&#xa0; Figure 8. Taiwan-focused decoy document.&#xa0;Outside Taiwan, Talos recovered a two-page decoy titled &#x201c;CSIS Indo-Pacific Forecast 2026 (Event Details).&#x201d; The document borrowed the framing of a legitimate event and referenced real experts, presenting an agenda focused on regional alliances, gray-zone security, demographic trends, and human security. The subject matter would plausibly appeal to government, diplomatic, think tank, academic, and security policy audiences across the Indo-Pacific, including readers focused on India.&#xa0; Figure 9. Indo-Pacific policy-themed decoy document.&#xa0;Beyond the recovered decoys, file names of malicious executables, HTA files, and WSF stagers revealed additional themes spanning maritime policy, foreign affairs, diplomatic events, human rights, government administration, and technology research.&#xa0; One lure shows how the actor exploited current geopolitical developments. &#x201c;Trump&#x2019;s Former Russia Adviser Claims Moscow Offered US Free Rein in Venezuela in Exchange for Ukraine&#x201d; closely paraphrased an Associated Press report, with two related samples appearing on VirusTotal two days later.&#xa0;&#xa0; Together, these examples show the actor using both news-style headlines and official-sounding documents to target audiences interested in foreign affairs, international security, and government policy.&#xa0; The table below lists the likely audience for each lure. Where recipient details or decoy content were unavailable, assessments are based solely on file names and subject matter and do not confirm delivery or compromise.&#xa0; Lure or decoy title&#xa0; Potential target or audience&#xa0; 115&#x5e74;&#x5ea6;&#x85aa;&#x8cc7;&#x6240;&#x5f97;&#x6263;&#x7e73;&#x7a05;&#x984d;&#x8868;&#x8aaa;&#x660e; (Instructions for the 2026 Salary Income Tax Withholding Table)&#xa0; Taiwanese think tank&#xa0; Resolution on the Updated Chart of Bajo de Masinloc&#xa0; Likely Philippine public sector&#xa0; Trump&apos;s Former Russia Adviser Claims Moscow Offered US Free Rein in Venezuela in Exchange for Ukraine&#xa0; Foreign-policy, government, research, or media audiences interested in the topic.&#xa0; CrossBorder_Repression_Seminar_Agenda&#xa0; Likely human-rights, civil-society, diaspora, academic, or policy communities.&#xa0; the May 27 inauguration of the TPiE&#xa0; Regional political and civil-society audiences&#xa0; Tehran_Bilateral_Summit_Proceedings_May2026&#xa0; Likely diplomatic, foreign-affairs, or policy audiences following a Tehran-based bilateral meeting.&#xa0; Items likely to be considered in the next Cabinet meeting.T11065885611.doc.exe&#xa0; &#xa0;Indian government audiences&#xa0; UO -C-DAC (1)&#xa0; Indian government technology and research audiences&#xa0; The infection chain&#xa0;In the reviewed spear-phishing operations, the actor uses a five-stage infection chain that begins with an HTA stager. Later stages abuse unsafe BinaryFormatter deserialization and gadget chains in standard .NET assemblies to load and execute the final payload.&#xa0; Figure 10. Antino backdoor infection chain.Stage 1: HTA and WSF Stager&#xa0;The &#x201c;my-<project>.page[.]dev&#x201d; Cloudflare URL in the spear-phishing emails leads to the download of an HTA file that was executed by mshta.exe. It hides and resizes its window, emits a tracking request to an invariant Cloudflare Pages beacon, and imports the next JavaScript stage from a cloud-hosted location. The same general template appears across multiple campaign variants:&#xa0; Figure 11. HTA stager.&#xa0;The actor uses two cloud services to deliver the second-stage JavaScript:&#xa0; Cloudflare R2: &#x201c;pub-<32-character hexadecimal identifier>[.]r2[.]dev&#x201d;&#xa0;Amazon CloudFront: &#x201c;d2nq35tel3ucuo[.]cloudfront[.]net&#x201d;&#xa0;The fixed Cloudflare Pages hostname &#x201c;oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev&#x201d; appears across multiple reviewed HTA variants. A hidden image causes mshta.exe to send a request containing the lure title in the URL path and ?track in the query string. This could allow the operator to correlate HTA execution with a particular lure for campaign tracking.&#xa0;&#xa0; Talos also observed WSF stagers that perform the same role through Windows Script Host. They send an HTTP HEAD request to the tracking host name with the lure title in the URL path, then load the next JavaScript stage from Cloudflare R2. Although paired HTA and WSF samples use different R2 objects and obfuscated loaders, both lead to the same infection chain.&#xa0;&#xa0; Figure 12. WSF stager script.Stage 2: HTA-hosted JScript downloader and decryptor&#xa0;The Stage 2 component is HTA-hosted Microsoft JScript, delivered from Cloudflare R2 and loaded in-process by mshta.exe through the HTA stager. It acts as a downloader and decryptor that prepares the next stage in-memory .NET deserialization chain. The script retrieves three encrypted resources from the cloud-hosted delivery infrastructure:&#xa0; Encrypted JavaScript orchestrator (.js file)&#xa0;Encrypted .NET serialized gadget resource 1 (.txt file)&#xa0;Encrypted .NET serialized gadget resource 2 (.txt file)&#xa0;After downloading the files, the script applies custom Base64 decoding and decrypts each response with RC4 using an embedded key. It then executes the decrypted JScript orchestrator in memory to initiate the .NET 4.x deserialization chain.&#xa0; Figure 13. HTA-hosted JScript downloader and decryptor.&#xa0;Stage 3: .NET BinaryFormatter deserialization chain&#xa0;The three files downloaded from Cloudflare R2 or Amazon CloudFront are the JScript orchestrator and two serialized .NET gadget resources. The threat actor leverages a scripted .NET deserialization technique in which JScript instantiates COM-visible .NET classes and passes attacker-controlled serialized data into BinaryFormatter. During deserialization, the embedded gadget chain drives execution, allowing the malware to load and execute an embedded .NET assembly, the next-stage &#x201c;TestAssembly.dll&#x201d;, inside the script host process, mshta.exe.&#xa0; Figure 14. JScript orchestrator.&#xa0;The JScript orchestrator deserializes the two resources in sequence. It first attempts to deserialize stage_1, which appears designed to disable a .NET security check introduced to block ActivitySurrogateSelector-based deserialization gadget chains. The code wraps this operation in a try/catch block and proceeds to stage_2 when an exception occurs, suggesting the actor anticipated differences in .NET versions, patch levels, or assembly availability across target systems. The two-call behavior observed in stage_1 appears intended to improve compatibility across different .NET patch levels.&#xa0;&#xa0; The second serialized resource, stage_2, uses the System.Windows.Forms.AxHost+State deserialization gadget in combination with an ActivitySurrogateSelector gadget chain. This technique substitutes a surrogate object during deserialization to drive code execution. In this case, the gadget chain loads the embedded PE file, &#x201c;TestAssembly.dll&#x201d;, directly into memory and executes it inside mshta.exe.&#xa0; Stage 4: &#x201c;TestAssembly.dll&#x201d; downloader and launcher&#xa0;&#x201c;TestAssembly.dll&#x201d; is a small .NET downloader and launcher that Stage 3 loads directly into mshta.exe through the BinaryFormatter deserialization chain. It downloads a lure-specific decoy document and a three-file DLL-sideloading bundle from cloud-hosted infrastructure. It opens the decoy, writes the bundle to a writable staging directory, and launches the Microsoft-signed &#x201c;GatherOsState.exe&#x201d;, which sideloads &#x201c;slc.dll&#x201d;, the Antino backdoor.&#xa0; The table below shows the files retrieved during one Taiwan-targeting campaign. Note that the actor uses randomized nonstandard extensions (.luy, .pzs, .syk) that remove obvious executable/DLL filename signaling.&#xa0;&#xa0; CDN URL&#xa0; Actual Content&#xa0; Description&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6Z[&#x2026;].pdf&#xa0; Lure-specific PDF&#xa0; Decoy document opened for the victim&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6ZGatherOsState.exe.luy&#xa0; GatherOsState.exe (legitimate signed binary)&#xa0; Legitimate signed binary that loads slc.dll&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6Zslc.dll.pzs&#xa0; slc.dll (Antino C2 implant)&#xa0; &#xa0;Antino backdoor&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6ZOsGather.dat.syk&#xa0; OsGather.dat&#xa0;&#xa0; Calculator decoy PE&#xa0; All the &#x201c;TestAssembly.dll&#x201d; downloader builds recovered in this investigation share the AssemblyAttribute GUID b2b3adb0-1669-4b94-86cb-6dd682ddbea3. This is a useful tooling-level detection marker.&#xa0;&#xa0;&#xa0; Figure 15. .NET assembly metadata for the TestAssembly component.&#xa0;Stage 5: Signed-host DLL sideloading Antino backdoor&#xa0;The downloaded &#x201c;GatherOsState.exe&#x201d; is a legitimate Microsoft-signed Windows Assessment and Deployment Kit (ADK) binary that was abused for DLL sideloading. When executed, it loads &#x201c;slc.dll&#x201d; from its local directory. The attacker placed the Antino backdoor file slc.dll alongside the signed executable, which then calls the DLL&#x2019;s SLOpen export to start Antino.&#xa0; C2 infrastructure&#xa0;Beyond email delivery, UAT-11587 relied extensively on Cloudflare throughout the infection chain. Cloudflare Pages hosted malicious HTA and WSF files and a separate execution-tracking endpoint, while Cloudflare R2 stored encoded loader stages, decoy documents, and payload components. UAT-11587 also used Amazon CloudFront to deliver additional scripts and decoy content. This architecture placed much of the infection chain within widely used cloud services and ordinary HTTPS traffic.&#xa0; We also identified software-themed domains that directly hosted standalone Antino executables. The domain &#x201c;microsoft-flash[.]com&#x201d;, registered shortly before its use, served Antino samples from &#x201c;https://microsoft-flash[.]com/download/flashcenter_pp_ax_install_en.exe&#x201d;. Similarly, &#x201c;wps-cn[.]com&#x201d; delivered a related Antino build from &#x201c;https://www.wps-cn[.]com/downloads/flashcenter_pp_ax_install_en.exe&#x201d;. The choice of &#x201c;wps-cn[.]com&#x201d; may also indicate that the delivery site was designed to appeal to Chinese-speaking users, particularly those in mainland China.&#xa0; While the infection chain relied heavily on Cloudflare, Antino itself used Microsoft 365 for post-compromise C2. The &#x201c;Dead-drop C2 communication&#x201d; section explains this channel in more detail.&#xa0; The Antino backdoor&#xa0;Antino is a , Rust-compiled Windows backdoor observed in both 32-bit and 64-bit builds. Talos named the malware after identifying AntinoApp in its Windows application manifest and repeated antino directory names in PDB and Rust source paths across multiple variants. It supports host reconnaissance, command execution, persistence, and Microsoft Graph-based C2, using Outlook for command exchange and OneDrive for heartbeat and file transfer.&#xa0; Figure 16. The Windows application manifest identifies the program as AntinoApp.&#xa0; D:\\a\\antino\\antino\\target\\x86_64-pc-windows msvc\\release\\deps\\slc_template.pdb&#xa0; D:\\a\\antino\\antino\\target\\x86_64-pc-windows-msvc\\release\\deps\\antino_client_template.pdb D:\\a\\antino\\antino\\target\\i686-pc-windows-msvc\\release\\deps\\antino_client_template.pdb D:\\a\\antino\\antino\\client\\src\\core.rs D:\\a\\antino\\antino\\client\\src\\signaller\\mod.rs D:\\a\\antino\\antino\\client\\src\\artillery\\run.rs D:\\a\\antino\\antino\\client\\src\\config\\mod.rs D:\\a\\antino\\antino\\shared\\src\\command_client.rs D:\\a\\antino\\antino\\shared\\src\\command\\registry.rs D:\\a\\antino\\antino\\shared\\src\\command\\add_to_run.rs D:\\a\\antino\\antino\\shared\\src\\command\\cmd.rs D:\\a\\antino\\antino\\shared\\src\\command\\download_file.rs D:\\a\\antino\\antino\\shared\\src\\command\\execute_program.rs D:\\a\\antino\\antino\\shared\\src\\command\\exit.rs D:\\a\\antino\\antino\\shared\\src\\command\\list_files.rs D:\\a\\antino\\antino\\shared\\src\\command\\load.rs D:\\a\\antino\\antino\\shared\\src\\command\\ps.rs D:\\a\\antino\\antino\\shared\\src\\command\\system_info.rs D:\\a\\antino\\antino\\shared\\src\\command\\upload_file.rs The &#x201c;D:\\a\\antino\\antino\\...&#x201d; paths follow the standard GitHub Actions Windows workspace structure, &#x201c;D:\\a\\<repository>\\<repository>\\...&#x201d;. This suggests that the reviewed CI variants were compiled on GitHub-hosted Windows runners.&#xa0; The backdoor was observed in both standalone executable and DLL forms. Our analysis observed two generations of Antino, distinguished by consistent differences in their underlying code and Rust build environment. The clearest implementation differences involve session-ID generation and registration and heartbeat behavior.&#xa0;&#xa0;&#xa0; Characteristic&#xa0; Antino Gen1&#xa0; Antino Gen2&#xa0; Observed build period&#xa0; October 2025&#xa0; December 2025 to January 2026&#xa0; Application identity&#xa0; No AntinoApp manifest in the reviewed builds&#xa0; Uses the AntinoApp application manifest&#xa0; Session identifier&#xa0; XOR- and Base64-encodes the process ID, computer name, username and platform.&#xa0; Generates a random UUID v4 containing no host-derived information&#xa0; Registration and heartbeat&#xa0; Classic builds use sendsession and heartbeat email drafts; an early DLL already supports OneDrive heartbeats&#xa0; Stores JSON heartbeat objects under &#x201c;/antino/heartbeats/<session_id>.json&#x201d;; the heartbeat also registers the implant&#xa0; Dead-drop C2 communication&#xa0;Antino communicates exclusively through Microsoft 365, using the Microsoft Graph API to interact with Outlook and OneDrive as dead-drop C2 channels. Both Antino generations use broadly similar Microsoft 365-based C2 workflows. This design allows Antino&#x2019;s C2 traffic to blend into legitimate Microsoft application synchronization at the network layer. Outbound connections terminate at &#x201c;graph.microsoft.com&#x201d; and &#x201c;login.microsoftonline.com&#x201d;, both of which are widely trusted and commonly allowed in enterprise environments.&#xa0;&#xa0; The Antino Gen2 implant authenticates to Microsoft Graph using the OAuth 2.0 client-credentials flow. This authentication method allows the registered Entra ID application to access the configured Outlook mailbox and OneDrive resources without requiring an interactive user sign-in.&#xa0; The Antino implant uses two distinct mechanisms for C2 communication, implemented in separate modules:&#xa0; Mechanism 1: OneDrive file-based communication&#xa0; The Antino backdoor uses the threat actor&#x2019;s OneDrive for registration and file-based communication. The OneDrive folder used for communication includes three folder paths:&#xa0; Path&#xa0; Direction&#xa0; Purpose&#xa0; /antino/heartbeats/{id}.json&#xa0; Antino upload&#xa0;&#xa0; Beacon / check-in; carries system state&#xa0; /antino_downloads/{file}&#xa0; Antino upload&#xa0; Exfiltrated data from victims (files the operator downloads from victims)&#xa0; /antino_uploads/{file}&#xa0; Threat actor upload&#xa0; Toolkit delivery staging (files the operator uploads to victims)&#xa0; Antino uses the heartbeats folder to upload JSON-formatted heartbeat files containing host telemetry, including the session ID, timestamp, online/offline status, machine name, username, platform, and a campaign code defined in the backdoor configuration. Each implant session is assigned a randomly generated UUID, which is used as the heartbeat filename &#x201c;{session_id}.json&#x201d;. The implant uploads the heartbeat file to OneDrive during initial execution and resends every minute.&#xa0; Figure 17. Example heartbeat JSON.&#xa0;The directory naming is from the threat actor&#x2019;s perspective. &#x201c;antino_uploads/&#x201d; holds tools the operator pushes to victims, while &#x201c;antino_downloads/&#x201d; holds data the operator pulls from victims. The file-based polling model is characteristic of dead-drop C2 designs used to decouple operator activity from implant activity on the network.&#xa0; Mechanism 2: Outlook commands communication&#xa0; The Antino backdoor receives commands through email messages. The implant actively pulls commands from the threat actor&#x2019;s Outlook mailbox folder every 10 seconds. The protocol uses two message types: command emails contain tasking from the controller, while response emails contain the implant&#x2019;s results.&#xa0; Command messages are identified by the subject prefix command_req_[session_id] and responses by command_res_[session_id], as indicated in the HTTP GET request sent by Antino:&#xa0; Figure 18. Request from Antino to Outlook to get commands from emails.&#xa0;&#xa0;The body of each command message contains a JSON object with the information required for execution. It has three fields: command_type, the command to invoke; command_data, an object containing command-specific parameters; and request_id, a per-command identifier used to correlate the request with the corresponding response (the request_id is distinct from the implant session_id used in the message subject and heartbeat). For example, a cmd request has this body:&#xa0; Figure 19. The JSON sent in command request message.&#xa0;&#xa0;The response follows a similar structure. Its body contains a JSON object describing the outcome of command execution. The command_type field identifies the command that was executed, while request_id links the response to the corresponding request. The success field indicates whether the command succeeded, result contains the returned output, and error provides failure details or is null when execution succeeds. For example, a successful cmd response has the following body:&#xa0;&#xa0; Figure 20. The JSON sent in command response message.&#xa0;Antino-supported commands&#xa0;Antino is a comprehensive backdoor that supports several commands for host reconnaissance and execution. Across the reviewed Antino builds, Talos identified the following command handlers. Command availability varies by generation and build.&#xa0;&#xa0;&#xa0; Command/handler&#xa0; Capability&#xa0; cmd&#xa0; Runs cmd.exe /C and captures output&#xa0; powershell&#xa0; Runs powershell.exe -Command&#xa0; system_info&#xa0; Collects host and process context&#xa0; execute_program&#xa0; Executes an operator-supplied program&#xa0; list_files&#xa0; Enumerates a directory&#xa0; upload_file&#xa0; Transfers files from the threat actor&#x2019;s OneDrive to the compromised host&#xa0; download_file&#xa0; Exfiltrates files from the compromised host to the threat actor&#x2019;s OneDrive&#xa0; load_shellcode&#xa0; Runs operator-supplied shellcode in memory&#xa0; add_to_run&#xa0; Establishes Antino persistence by adding a Registry Run value&#xa0; exit&#xa0; Stops the Antino runtime&#xa0; Antino-supported commands. Command availability varies slightly by generation and build.&#xa0; The cmd and powershell commands allow the operator to execute commands directly through the Windows command shell or PowerShell and collect their output.&#xa0;&#xa0;&#xa0; Filesystem operations are handled through list_files, upload_file, and download_file. Similar to the C2 communication protocol, these names are written from the operator&#x2019;s perspective: upload_file transfers files from the threat actor&#x2019;s OneDrive to the compromised endpoint, while download_file reads a file from the endpoint and uploads it to OneDrive for operator retrieval.&#xa0;&#xa0; Antino provides two options for running actor-supplied code: load_shellcode and execute_program. The load_shellcode command sends a Base64-encoded payload in the command-request email body in the following JSON format:&#xa0; Figure 21. The load_shellcode command structure.Masking the loaded payload&#xa0; The use_sleep_mask parameter enables a defense evasion technique intended to reduce the secondary payload&#x2019;s exposure to memory scanners. When enabled, Antino hooks Sleep and VirtualAlloc and registers a vectored exception handler (VEH). The VirtualAlloc hook records the tracked memory region. When the tracked payload thread calls Sleep, the Sleep hook changes that region to non-executable (PAGE_READWRITE), encrypts its contents in place, and then calls the real Sleep function.&#xa0; &#xa0;After Sleep returns, an attempt to execute code from the encrypted, non-executable region triggers an access violation. The VEH confirms that the fault occurred within the tracked region, restores its previous memory protection, decrypts the content, and resumes execution. This technique is intended to reduce the time during which memory scanners can observe recognizable executable payload bytes. Although this technique does not mask the entire Antino process or guarantee evasion, it adds another layer of defense evasion by reducing the window in which memory scanners can identify the loaded payload.&#xa0; Abuse of the Windows Scripted Diagnostics framework workflow&#xa0;&#xa0; The Antino backdoor abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components. Both the execute_program and add_to_run commands use this technique.&#xa0; This workflow involves three components:&#xa0;&#xa0; Scripted Diagnostics Execution Engine (&#x201c;sdiageng.dll&#x201d;)&#xa0;Program Compatibility Wizard (PCW) troubleshooting package (&#x201c;C:\\Windows\\diagnostics\\system\\PCW&#x201d;)&#xa0;&#xa0;Scripted Diagnostics Native Host process (&#x201c;sdiagnhost.exe&#x201d;)&#xa0;Windows normally uses &#x201c;sdiageng.dll&#x201d; to load troubleshooting packages such as PCW, while &#x201c;sdiagnhost.exe&#x201d; executes their PowerShell scripts in a separate process.&#xa0; Antino initializes COM and creates an instance of CLSID {1F3D8AA5-9EBF-4EE4-85C2-EA40379AEDE8}, the CScriptedDiag class implemented by &#x201c;sdiageng.dll&#x201d;. It then initializes the engine with the legitimate PCW package and a blank diagnostic Answers XML document. The engine creates a temporary working copy of the package and returns its directory, such as &#x201c;C:\\Windows\\Temp\\SDIAG_<GUID>&#x201d;.&#xa0; Antino writes an attacker-controlled PowerShell script into this directory. For example, the add_to_run command generates a script that creates an HKCU Run key value:&#xa0; Figure 22. PowerShell script generated by Antino&#x2019;s add_to_run command.Antino then resumes the diagnostic workflow. The Scripted Diagnostics engine delegates execution to the native host, observed in runtime traces as %windir%\\SysWOW64\\sdiagnhost.exe -Embedding. The host subsequently executes result.ps1. The resulting Run key entry launches the selected Antino executable the next time the affected user signs in.&#xa0; &#xa0;The technique allows Antino to proxy PowerShell execution and the persistence-related registry modification through a Microsoft-signed diagnostic workflow. This can complicate behavioral attribution to the original implant, although it does not eliminate observable PowerShell, file-creation or registry telemetry.&#xa0; Figure 23. Antino calls CoCreateInstance to activate the Windows diagnostic COM class.&#xa0;Antino configuration&#xa0;&#xa0;Antino stores the configuration data in a custom PE section named .cfg. The on-disk structure begins with a four-byte little-endian JSON length followed by bytes XORed with the alternating key 0xAB 0xCD.&#xa0;&#xa0; In addition to its C2 configuration, Antino&#x2019;s embedded configuration contains two deployment settings, run and launch_mode. The run field controls whether Antino automatically installs a persistent copy when it starts. When set to true, Antino launches its installation task, stages the required files under %LOCALAPPDATA%\\Windows GatherOSStateKit\\, and creates an HKCU Run value. launch_mode is evaluated only when run is set to true. It defines which files constitute the persistent payload: exe or raw for standalone PE or dll for sideloading.&#xa0; Coverage&#xa0;The following ClamAV signatures detect and blocks this threat:&#xa0;&#xa0; Html.Trojan.UAT-11587-10060367-2&#xa0;Txt.Trojan.UAT-11587-10060385-5&#xa0;Txt.Trojan.UAT-11587-10060386-1&#xa0;Win.Trojan.UAT-11587-10060365-1&#xa0;Win.Trojan.UAT-11587-10060366-1&#xa0;Win.Trojan.UAT-11587-10060369-1&#xa0;Win.Trojan.UAT-11587-10060370-1&#xa0;Win.Trojan.UAT-11587-10060371-1&#xa0;Win.Trojan.UAT-11587-10060372-1&#xa0;Win.Trojan.UAT-11587-10060373-1&#xa0;Win.Trojan.UAT-11587-10060374-1&#xa0;Win.Trojan.UAT-11587-10060375-1&#xa0;Win.Trojan.UAT-11587-10060376-1&#xa0;Win.Trojan.UAT-11587-10060377-1&#xa0;Win.Trojan.UAT-11587-10060378-1&#xa0;Win.Trojan.UAT-11587-10060379-1&#xa0;Win.Trojan.UAT-11587-10060380-1&#xa0;Win.Trojan.UAT-11587-10060381-1&#xa0;Win.Trojan.UAT-11587-10060382-1&#xa0;Win.Trojan.UAT-11587-10060383-1&#xa0;Win.Trojan.UAT-11587-10060384-1&#xa0;The following Snort rules cover this threat:&#xa0;&#xa0; Snort 2: 1:66880, 1:66881, 1:66882&#xa0;Snort 3: 1:66880, 1:66881, 1:66882&#xa0;Indicators of compromise (IOCs)&#xa0;&#xa0;IOCs for this research can also be found at our GitHub repository here.&#xa0; e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 (malicious HTA stager - CSIS Indo-Pacific lure)&#xa0; e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf (malicious HTA stager - Bajo de Masinloc lure)&#xa0; 4d0fdce4c098635fe9b296c3a82c74645f9885eb5e383aa44a0fe7e50da3ca3f (malicious HTA stager - Taiwan information-warfare workshop lure)&#xa0; f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 (malicious HTA stager - Taiwan legislative-tax lure)&#xa0; 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a (malicious HTA stager - Venezuela and Ukraine news lure)&#xa0; 5a35fcd4458e808ab0fa52bb2a92923b60566ee4d7aaadaac7c95cad3d839562 (malicious HTA stager - Venezuela and Ukraine news lure)&#xa0; 17b53ffa8e005f0e82491d3f9c0a4984c44da52e1668a855c11a137f627c5b4b (malicious HTA stager - institutional disciplinary-action lure)&#xa0; 484ab497072ea09f12187b349f5b1c80754e4942408a009cccb20a2a3c8c6506 (malicious WSF stager - institutional disciplinary-action lure)&#xa0; 3a94910eb8022592ce030e6861359f7e980fc1b5a6ccd290cbb071d3e95ed02a (malicious HTA stager - TPiE inauguration lure)&#xa0; 6a1dbbfcfe6867ac83d35012b2717084388b4a34707efd0b725466dfd0e8fa56 (malicious WSF stager - TPiE inauguration lure)&#xa0; 75c12795016ae48b1bddd34a9f5adea63a12f58701eae01e1b4ab3d9dfa1513c (malicious HTA stager - Tehran bilateral-summit lure)&#xa0; bd8ddc8f33e0fe43147ee6f1713654996420a27c5d2cd91751ad67124ebc6fe4 (malicious WSF stager - Tehran bilateral-summit lure)&#xa0; b75492466462141c56d97b705f0c606faf272577631dc2822aa8d6bda53633b6 (malicious HTA stager - cross-border repression seminar lure)&#xa0; 23d5f1af8581ae200615d9a66d539f2043c3248b649e862557b379d7e8b7a3ac (malicious WSF stager - cross-border repression seminar lure)&#xa0; 0b4e5e017c0f0ccac79e13ca5d580a75af67a24ca0763f9ebfdaaeb1ba4fc739 (malicious HTA stager - Latin carnival lure)&#xa0; ae1b45fb56b9f1b9cb3ee30d2bb1279c9b90b70bb62f8de305d198c6a4e0585e (malicious WSF stager - Latin carnival lure)&#xa0; cd3509fa82e506cc6f2eeafa0a45d4b8b76a07edadd29779daf00568febcaba7 (malicious HTA stager - C-DAC lure)&#xa0; b8e6e83a73e6e07f8873c364dd2a4b830bceb60758163e2efcd7e387cb604655 (malicious WSF stager - C-DAC lure)&#xa0; 7969ae5f11fc163049c8eadba06f814f5edece13a707e6087c1c49011a45b838 (malicious HTA stager - Latin carnival lure variant)&#xa0; aea5e9029f9212d05bde10f7806d1f2819be45d167e6fd877b9fb1b11088ac90 (malicious WSF stager - Latin carnival lure variant)&#xa0; 7fa98efba59614cec0b7291aedee98764f8dc037b6cc798c93951a31208e9e32 (malicious HTA stager - internal-review lure)&#xa0; 65f4b9292e91abfa5adf42a03526932930c1c0a436bb186a7948fe6770295788 (malicious WSF stager - internal-review lure)&#xa0; 61a8f5add6c35f99c389012dbb2343061fd0b54611b40490b9a7f0b49d707da0 (Antino-chain Stage 2 JScript downloader and decryptor)&#xa0; 747b1d13bdf06956b5da5f47250fefd5284ebcf7961971732c3d348aa1a2d533 (Antino-chain Stage 2 JScript downloader and decryptor)&#xa0; a13182699a12a8dd9d07c336dbd8de5e9b086b9b09793b7de2e9761aa03ce1dc (Antino-chain Stage 2 JScript downloader and decryptor)&#xa0; 2f1513c822af0c6635dd3c69dc38f0b2f6e02012ea36415fff111a5d4d5fae05 (Antino-chain Stage 2 JScript downloader and decryptor)&#xa0; a0e91085f08956a9a7034ace73cee60cb211f5d96f02bc91a026601bde8f2221 (Antino-chain Stage 2 JScript downloader and decryptor - HTA branch)&#xa0; 47f98dfe01759a464e22d5ec55d012dccb38ce010dd73e3ba8d7ffefca12b4b2 (Antino-chain Stage 2 JScript downloader and decryptor - WSF branch)&#xa0; b3416726a064dd7f657bbb400adeb365eea7f8bb60783ad2d9da1a1d93768731 (Antino-chain Stage 2 JScript downloader and decryptor - HTA branch)&#xa0; 0a6fb71ab1362d065c7ec2678c1e73d9a0721b0e7099d392ba7559bb2eec4970 (Antino-chain Stage 2 JScript downloader and decryptor - WSF branch)&#xa0; f0c1dc6d6daa4d010932c7818ed5f22929c182f58e5f495fabe2fb3cfc835b97 (Antino-chain encrypted JScript orchestrator)&#xa0; 5555e904101689351a2a1359c9c06da0a57139a9470df7d26823c1b75db55041 (Antino-chain encrypted BinaryFormatter resource)&#xa0; 5168a2696a0ed858f996f388bfe94f952d475158f4ee6206816608936db005ca (Antino-chain encrypted BinaryFormatter resource)&#xa0; 7c2ac9c040b3300bffa7d2e435dbb1bc12e7efd644d2216d603c72121266395c (Antino-chain encrypted JScript orchestrator)&#xa0; d87201c1299a7f5854929645e6891c6c424d2a690031272bedacba7c5fe73a3e (Antino-chain encrypted BinaryFormatter resource)&#xa0; 334f39279ff3aae40fe74340c887ae018c75bc42790586bdf9070adb5889100c (Antino-chain encrypted BinaryFormatter resource)&#xa0; 077bd873217d8abfbb6482d11966ca34f3fef7ad5166f24fbc5dc3ddefe894a1 (Antino-chain encrypted JScript orchestrator)&#xa0; ad0bd2b45e2416fb1384bf30af068d857e7c06b4226615d66b55b610a34c5670 (Antino-chain encrypted BinaryFormatter resource)&#xa0; e2f59d8d5a81583ed482b6c7bf37699efdb2264e452cf7d8cfc0c54dfbd9ab3f (Antino-chain encrypted BinaryFormatter resource)&#xa0; 3a4c9020eeb5ef22a1ff443e606ccb6705fe287c583121c713d2c9f9f1f2a2af (Antino-chain encrypted JScript orchestrator)&#xa0; 4b614e5c37abaddca162119e42a969945caa681305e246e0ed0060ea9984008b (Antino-chain encrypted JScript orchestrator)&#xa0; c8e1239d7276178b6620f47ec4880494be1cb394477b223fc54bffb0947bff50 (Antino-chain encrypted BinaryFormatter resource)&#xa0; 079acd58a74479ac8b108b618d2a4da8a8bd560a04459cd90e2fec9da5027513 (Antino-chain encrypted BinaryFormatter resource)&#xa0; 8e1d68906d6de92f359945d3a95da1480e72773a3e8dea7682d6bf0f6699f75f (Antino-chain encrypted JScript orchestrator)&#xa0; 170b0eee60a335f32c1d0c19a0bb8d8bbc0a5b298ea9486b546f58d25cc8a464 (Antino-chain encrypted BinaryFormatter resource)&#xa0; b31ca75f73a9363b0e35042a41216c3f581eaa0b9cd78cb58f089c2e40babd40 (Antino-chain encrypted BinaryFormatter resource)&#xa0; d753a615aedf8e58ffc75b2b7ebd320c0cbe6bcb5cbb885db749a2a85c55d3bf (Antino-chain TestAssembly.dll downloader)&#xa0; 133a46ba41136ca21c93fb08c28446826d8c0d9b7923a16f2d152d595a710098 (Antino-chain TestAssembly.dll downloader)&#xa0; 9fc50cf28f86201fda8306926817b1ede41fdd993202515905dd072f6803542f (Antino-chain TestAssembly.dll downloader)&#xa0; d4cb2f5df16ec9b9c5b796ae55848534e15d4f8b8806f0431108fc7a99a2548a (Antino-chain TestAssembly.dll downloader)&#xa0; 131ac3e0df777910e0a32e43d5744bccb0490750d4c2adc359da41d76d383c46 (Antino-chain TestAssembly.dll downloader)&#xa0; 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff (Antino Gen 2 slc.dll backdoor)&#xa0; 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd (Antino Gen 2 standalone fake-installer backdoor)&#xa0; 1fadc90b61ce536abda78eb387a7f3d745f00c16775d3f762845ccc0fde567da (Antino Gen 1 slc.dll backdoor)&#xa0; 40e7e77aff603f4c2ef17b3bc8ea836e714d0734a1e5b946e52f95536ec5c91d (configured Antino Gen 1 standalone backdoor)&#xa0; 5c5c060b272cd4a5c3767edc0e9478bd35b7e1756e183d0446a5491bd65519cb (configured Antino standalone backdoor)&#xa0; 971cb2448b5d67dcc1f5eaa10d12e77f213035ad31230dc2ac7a510610a2059d (Antino Gen 2 standalone fake-installer backdoor)&#xa0; 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 (Antino Gen 2 standalone fake-installer backdoor)&#xa0; b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e (Antino Gen 2 standalone fake-installer backdoor)&#xa0; ca14ad0344dc7216f6da29a5cbe4237d886cc5257e8c3a48fb4885a311c9b800 (post-unpack Antino standalone backdoor memory image)&#xa0; e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 (Antino Gen 2 slc.dll backdoor)&#xa0; e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb (Antino Gen 2 slc.dll backdoor)&#xa0; fdbd047031c13a17c9f491c9355f44d587584ebe2b8927be8482e6c236c8e1c1 (Antino Gen 2 slc.dll backdoor)&#xa0; 103[.]27[.]110[.]220 (historical serving IP for the Antino payload hosted on wps-cn[.]com)&#xa0; osc-cdn[.]com (actor-used spear-phishing sender domain)&#xa0; oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev (Cloudflare Pages execution-tracking domain)&#xa0; d2nq35tel3ucuo[.]cloudfront[.]net (Antino-chain CloudFront staging domain)&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev (Antino-chain Cloudflare R2 staging domain)&#xa0; pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev (Antino-chain Cloudflare R2 staging domain)&#xa0; my-3lyt6wcp[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-qc39r814[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-662ylt3w[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-6g16qsfe[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-goq6xmbm[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-h3qli6kq[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-sv7c1fzs[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-u0up9qri[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-vtsdod2n[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-wgoxp32b[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; microsoft-flash[.]com (standalone Antino fake-installer delivery domain)&#xa0; wps-cn[.]com (standalone Antino fake-installer delivery domain)&#xa0; hxxps://microsoft-flash[.]com/download/flashcenter_pp_ax_install_en.exe (standalone Antino fake-installer delivery URL)&#xa0; hxxps://www[.]wps-cn[.]com/downloads/flashcenter_pp_ax_install_en.exe (standalone Antino fake-installer delivery URL)&#xa0; hxxps://my-662ylt3w[.]pages[.]dev/Institutional_Disciplinary_Action_Report_May_2026.hta (malicious HTA delivery URL)&#xa0; hxxps://my-662ylt3w[.]pages[.]dev/Institutional_Disciplinary_Action_Report_May_2026.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-6g16qsfe[.]pages[.]dev/the%20May%2027%20inauguration%20of%20the%20TPiE.hta (malicious HTA delivery URL)&#xa0; hxxps://my-6g16qsfe[.]pages[.]dev/the%20May%2027%20inauguration%20of%20the%20TPiE.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-goq6xmbm[.]pages[.]dev/Tehran_Bilateral_Summit_Proceedings_May2026.hta (malicious HTA delivery URL)&#xa0; hxxps://my-goq6xmbm[.]pages[.]dev/Tehran_Bilateral_Summit_Proceedings_May2026.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-h3qli6kq[.]pages[.]dev/CrossBorder_Repression_Seminar_Agenda.hta (malicious HTA delivery URL)&#xa0; hxxps://my-h3qli6kq[.]pages[.]dev/CrossBorder_Repression_Seminar_Agenda.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-sv7c1fzs[.]pages[.]dev/Extravaganza%20Latin%20Carnival.hta (malicious HTA delivery URL)&#xa0; hxxps://my-sv7c1fzs[.]pages[.]dev/Extravaganza%20Latin%20Carnival.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-u0up9qri[.]pages[.]dev/UO%20-C-DAC%20%281%29.hta (malicious HTA delivery URL)&#xa0; hxxps://my-u0up9qri[.]pages[.]dev/UO%20-C-DAC%20%281%29.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-vtsdod2n[.]pages[.]dev/Extravaganza%20Latin%20Carnival%20post%20copy.hta (malicious HTA delivery URL)&#xa0; hxxps://my-vtsdod2n[.]pages[.]dev/Extravaganza%20Latin%20Carnival%20post%20copy.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-wgoxp32b[.]pages[.]dev/Internal_Review_Dossier_0520.hta (malicious HTA delivery URL)&#xa0; hxxps://my-wgoxp32b[.]pages[.]dev/Internal_Review_Dossier_0520.wsf (malicious WSF delivery URL)&#xa0; hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/4oyE4n4ozLQ0.log (Antino-chain Stage 2 URL)&#xa0; hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/LtVGUSsyUTDA.log (Antino-chain Stage 2 URL)&#xa0; hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/TzzyYlYnJ40Z.log (Antino-chain Stage 2 URL)&#xa0; hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/tdyvHHVcrci8.log (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/Qw7Womin4X6N (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/kVFPxm1uAjOY (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/5SVIdjpRQjkZ (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/PbyfSk69AwVf (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/qMD71Z95clTf (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/HenUWB51MwpG (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/q9LgxIaU1CJK (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/BKvYRxPiGpbM (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/nswz3cb9lhuC (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/6HJV5qV5BTLs (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/MKJacn3hFt3Y (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/cX8MChhuVvzz (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/byrdvvZEZZlk (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/5TGrbjCCLa8M (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/s0p18dgHR4PZ (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/zlKDeyO3HuUS (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/icWMOGLJcfQO (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/5U7kzhvlYlVF (Antino-chain Stage 2 URL)&#xa0; hxxps://d2nq35tel3ucuo[.]cloudfront[.]net/9q9OlLKCm0an2ct1.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://d2nq35tel3ucuo[.]cloudfront[.]net/LwqPW64Xl0ti3q7s.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://d2nq35tel3ucuo[.]cloudfront[.]net/HsOw0YU9s11dxyr1.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/0u25lAqY58or53ra.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/gpv0IRMtvto6e8t2.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/HzjNPgRE9ir92e38.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/2laZiB2zvnx04jze.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/wyLwwCu43j1wf2pg.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/ThyI9pwewrh_a1pr.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/8ypvQLxJvggmrz94.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/vD68BdmB2ky28gcc.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/oaFE7PJHk0h_emqt.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/AcPP9fCvdjztmho8.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/7ChyKauxbnuftp68.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/KOOOT4a76st012bx.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/Ub4RJzNIrfleri8t.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0;&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/HeiqAW6ZGatherOsState.exe.luy (Antino sideload-package URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/HeiqAW6Zslc.dll.pzs (Antino backdoor delivery URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/HeiqAW6ZOsGather.dat.syk (Antino sideload-package URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgGatherOsState.exe.lzj (Antino sideload-package URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgslc.dll.iwq (Antino backdoor delivery URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgOsGather.dat.ael (Antino sideload-package URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/bzP3NcRPGatherOsState.exe.thl (Antino sideload-package URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/bzP3NcRPslc.dll.czh (Antino backdoor delivery URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/bzP3NcRPOsState.dat.mxb (Antino sideload-package URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/VD7F3WxnGatherOsState.exe.mtm (Antino sideload-package URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/VD7F3Wxnslc.dll.fsc (Antino backdoor delivery URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/VD7F3WxnOsState.dat.pgy (Antino sideload-package URL)&#xa0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-spotlight","cisco-talos-dns-security","cisco-talos-malware-protection","cisco-talos-email-threat-prevention","geo:inferred"],"relatedCves":[],"titleFingerprint":"11587-across-antino-asia-backdoor-china-government-nexus-organizations-policy-targets-uat","countryCodes":["CN","HK","IN","KH","MM","PH","PK","RU","SG","TH","TW","UA","VE"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/","type":"report","title":"Cisco Talos: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T10:00:01.000Z","addedAt":"2026-09-30T10:52:59.012Z","updatedAt":"2026-09-30T10:52:59.012Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"61c78b57-4cb4-4bc2-ab68-eca447ac7f94","slug":"talos-uat-7810-continues-building-orb-networks-using-new-malware-2de0cf52","externalId":"6a3950a51157ca0001c2a7db","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"UAT-7810 continues building ORB networks using new malware","description":"Cisco Talos is actively tracking infrastructure and malware associated with UAT-7810, an advanced persistent threat (APT) actor responsible for maintaining and proliferating the LapDogs Operational Relay Box (ORB) network, first disclosed by SecurityScorecard in 2025.UAT-7810 is most likely tasked with establishing Operational Relay Box (ORB) networks that can then be leveraged by associated secondary threat actors to conduct their own malicious attacks against high value targets.Talos&#x2019; latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware, dubbed &#x201C;SHORTLEASH,&#x201D; with a newer version already being developed and hosted on attacker-controlled infrastructure. We track this new version of SHORTLEASH as &#x201C;LONGLEASH.&#x201D;Furthermore, we&#x2019;ve discovered two new malware families in UAT-7810&apos;s arsenal: a C-based backdoor we track as &#x201C;DOGLEASH&#x201D; and a JAVA-based backdoor we track as &#x201C;JARLEASH.&#x201D;Talos assesses with high confidence that UAT-7810 is a China-nexus threat actor based on the infrastructure that it provides to secondary China-nexus APTs such as UAT-5918. Open-source reporting has also illustrated overlapping tooling between UAT-5918 and UAT-7810. However, at this time, Talos considers UAT-5918 and UAT-7810 separate APT actors tasked with their own set of objectives and targets. Talos&#x2019; latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware dubbed &#x201C;SHORTLEASH&#x201D; with a newer version already being developed and hosted on attacker-controlled infrastructure. We track this new version of SHORTLEASH as &#x201C;LONGLEASH.&#x201D; Talos has also discovered two more previously unknown tools in UAT-7810&apos;s arsenal: DOGLEASH: A malicious backdoor that can execute arbitrary shellcode on the compromised Linux deviceLEASHTEST: A Linux binary (ELF) that is used for testing rudimentary functionality on MIPS-based embedded devicesTalos&#x2019; findings also illustrate that UAT-7810 used at least four new servers to host a variety of minor variations of DOGLEASH to deploy against compromised targets. An additional JAVA-based (JAR package) backdoor that we track as &#x201C;JARLEASH&#x201D; was also deployed by UAT-7810 on at least one of the three servers for administration purposes, including file management, FTP, SFTP, and Netcat. UAT-7810 exploits n-day vulnerabilitiesTalos has observed UAT-7810 primarily exploit known vulnerabilities in unpatched Ruckus wireless routers, a tactic UAT-7810 has used since 2025. CVEs exploited include: CVE-2020-22653CVE-2020-22658CVE-2023-25717UAT-7810 infrastructureTalos discovered four new servers being used by UAT-7810 to host malicious payloads for a variety of hardware platforms including MIPS, ARM, and x64. The malware hosted predominantly consists of DOGLEASH, and accompanying shell scripts are executed on compromised systems to download and execute DOGLEASH. All three of the following IP addresses were associated with VPS instances that indicated UAT-7810 acquired and used these servers as download locations: 194.233.92[.]26217.15.160[.]247217.15.164[.]147&#xA0;One of the IPs, &#x201C;217.15.164[.]147&#x201D;, was also used as infrastructure to conduct exploitation of ASUS&#x2019; AiCloud Routers in early 2026 &#x2014; specifically CVE-2025-2492 &#x2014; indicating that UAT-7810 or an associated threat actor likely attempted to expand their ORB network to AiCloud Routers. Additionally, &#x201C;217.15.160[.]247&#x201D; and &#x201C;217.15.164[.]147&#x201D;,&#xA0; hosted a TLS server on port 99 with the certificate fingerprint: c2ab9adaba93ff094b8f3fc37d906014d870582039d276b7bd03e6fd583d8a15 and subject_dn = \"C=exploit, ST=exploit, L=exploit, O=exploit, OU=exploit, CN=exploit\" Forensic analysis of compromised networking devices led to the discovery of a fourth IP address UAT-7810 used to host their malicious payloads: &#x201C;95.182.100[.]231&#x201D;, residing in Hong Kong. UAT-7810&apos;s malware suiteLONGLEASH: A new version of SHORTLEASHLONGLEASH is a new version of UAT-7810&apos;s previously disclosed backdoor SHORTLEASH. SHORTLEASH consisted of a backdoor capable of contacting its command and control (C2), hosting a web server, managing tunnels, and acting as both a C2 server and client. LONGLEASH, however, contains a variety of additional capabilities, indicating that UAT-7810 is actively developing it for use against their targets. LONGLEASH is built off the same codebase as SHORTLEASH, with both tools being internally named &#x201C;ff-agent&#x201D;. The LONGLEASH variant compiled for MIPS processors is built on the asynchronous version of the Boost library (Boost.Asio) to minimize the blocking time and maximize the performance of the network. The internal name for the LONGLEASH project is &#x201C;nz1.0&#x201D; and it has the following major components: Base: Contains the implant&#x2019;s logging and utilities, such as routines for Base58 and Base64 encoding and decoding.Executor: Supports several capabilities, including the main proxying functions, for setting up the following channels:Reverse shell to C2Proxy servers for HTTP, DNS, SOCKS, TCP, ICMP, and UDPPacket redirection for traffic based on TCP, UDP, and HTTPSMTP server and clientThe other major executor modules support managing of network connections to other servers, including TLS and public key infrastructure, managing clients connected to the implant, sockets and URIs. &#xA0;The executor is also tasked with authorization of clients, routing of the messages through the proxy network, and setting and management of basic network tunnels. &#xA0;Finally, the executor contains functionality to remove the implant and all traces from the server if a suspicious connection or tampering is detected. Core: Provides basic authorization and node identification services, HTTP encoding and utilities, processing of protocol buffer (protobuf) encoded messages, basic SHA checksum functions, task management, and basic security.The implant contains the User-Agent string \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.95 Safari/537.36\" which may allow it to hide within legitimate traffic purporting to be an instance of the Windows Chrome version 122. &#xA0;Apart from the Boost.Asio, the implant contains code from at least two open-source libraries: Nanopb, used for processing protobuf messages, and MbedTLS, for establishing TLS, proxying TLS encrypted communications, and managing x509 certificates for the network. The implant does not use a standard libc library but a small musl library libc that implements C functions on top of Linux syscalls. LONGLEASH also has the capability to act as an intermediate C2 server. It can obtain commands and data from the original C2 and forward to its peers. Figure 1. LONGLEASH&#x2019;s functional components.DOGLEASH: The passive backdoorTalos also discovered a previously unknown backdoor, developed and operated by UAT-7810, that we track as DOGLEASH. After compromising a networking device, UAT-7810 deploys a shell script that: Downloads DOGLEASH.Adds iptables rules to allow TCP traffic to a specific port, on which DOGLEASH binds and listens.Executes DOGLEASH on the device.Figure 2. Startup script for SHORTLEASH.DOGLEASH will bind and listen for an incoming request on a local hardcoded port. Any TCP data received is then decoded using a hardcoded password string. Based on the command code and accompanying data received, it creates a new thread in the process and carries out a specific action: Command code Action taken 0x2268, 0x2267 Execute command using /bin/sh -c 0x2266 Read file 0x2271 Rename file to create a backup 0x2273, 0x2274 Close socket listener 0x3450 Get OS info info -> release, version, machine HW ID, node name None of the above Execute code in memory JARLEASH: The JAVA-based administratorJARLEASH is a JAR-based backdoor that UAT-7810 deploys on their own infrastructure, as well as on compromised systems with JAVA available, to enable easy access to the system. JARLEASH is accompanied by a startup script that first kills any active instances of JARLEASH on the system, and then spawns the JAVA container to deploy JARLEASH. Figure 3. Startup script for JARLEASH.JARLEASH can either use an external configuration file or default to an embedded configuration. The configuration file contains comments in Simplified Chinese, indicating that the operators were Chinese-speaking individuals. The backdoor has the following capabilities: Host a web-based file management interfaceFTP and SFTP serversRun a netcat server on a specified IP and port numberFigure 4. JARLEASH core components.LEASHTEST: Testing the watersTalos also discovered a test binary UAT-7810 developed that we track as &#x201C;LEASHTEST.&#x201D; This binary is not malicious as-is, but its presence on a device likely indicates a compromise. It is used to test rudimentary functionality on the MIPS platform. Internally named \"iot-test\", it checks to see if it can take the following actions on an Internet-of-Things (IOT) device: Create a thread and join itBind and listen to a port to open up a TCP acceptorCreate a child process (sub program)Create an async timerPrint \"Hello World!\"Test exception handling routine&#xA0;The development and use of LEASHTEST signifies that even though they have developed LONGLEASH, a full-fledged backdoor framework, UAT-7810 is still actively testing functionality on MIPS platforms and may not be completely confident of its behavior on MIPS devices. CoverageSNORT&#xAE; SIDs for the threats detailed here are: 66433, 66432, 66430, 66431, 301493. ClamAV signatures for the malicious tooling associated with this cluster are: Unix.Backdoor.Agent-10059997-1Unix.Backdoor.Agent-10059998-0Unix.Backdoor.Agent-10059999-0Java.Backdoor.Agent-10060000-0Unix.Backdoor.Agent_mips32-10060001-0Unix.Backdoor.Agent_mips32r2-10060002-0Unix.Backdoor.Agent_armv7-10060003-0Unix.Backdoor.Agent_mips1-10060004-0Unix.Backdoor.Agent_mips32r2el-10060005-0Unix.Backdoor.Agent_mips32el-10060006-0IOCsNetwork indicators 194.233.92[.]26 217.15.160[.]247 217.15.164[.]147 95.182.100[.]231 http[:]//217.15.160[.]247:8088/ http[:]//217.15.160[.]247:2222/ http[:]//217.15.160[.]247:99/ http[:]//194.233.92[.]26:8088/ http[:]//194.233.92[.]26:2222/ http[:]//217.15.164[.]147:99/ http[:]//217.15.164[.]147:8088/ http[:]//217.15.164[.]147:2222/ http[:]//95.182.100[.]231:2222/ Malware indicatorsLEASHTEST 1b5649b479fd625de5c8120873644b5eb669cc89cd504582c18e0ae350fd8823 LONGLEASH 755fcee1337a252203002ecfdf673a08cfadeda8d738bef2d518a08e0626aa4f Startup script for JARLEASH e799d72929d7ccc7f6b6109742b8cc482838303207efc989543b6e1ca6d16e9c Configuration file for JARLEASH 3b89d183eb014e29d9d0d4e45fc2b784a7fcfcf31dd48fd3bde30f8d956383d1 JARLEASH 324d95024fc8da5c92b5a1f4825aed5a2a91c9ca8fb6aa52abb332a4c9cf4257 bafba443170e54ef7fd431ce7f1b5e202719f3fd022e4ef70788904f574d2cdf DOGLEASH 604b53f87d6c070bf387e80c70a6df8d272fa3fc143148d41f13e59d52ab1f13 c92541f273eeb576d39235d0a5c6f18f2574b132a1022598edfa38065783ab98 29c7fccc6ef8cbfe4da9a169c7c74bacaea1fb515a1fddef91ab1b1522f76e4c 425bf771c8c9f740b1ae9803dcb4fd45af4d6a6f171fcc72fc7d511095ca82ce ac8eae94d27122f4751bc96d9ea52d30000b7ca37569a2291b2710824ca3396f dc4f25b2247cfdd6fc96848db30a178baa4419a4c854e86e315b465836102d14 3878dd5c8eba1e5b53ab2e07e7b5482e95a3fd3e98268bcd7861318bc9902376 9b9e0e5a1eb469b8d20dc23351e08ff5d5731e1cedce0ddee9bbd00a76217f13 57bdab2ba4b05ec0338c06632599393d5b14227f31a43fe950ea8fdd47428715 b8d247fd1fb85d24a17afeec3815906dfbcdc5359647910b4a153900ec999a0f 5e225ea2648a8cba0fd94ec7fd8ce5315f5d0cc2922bafc9db3c8c41280e917c d5cf7315186a78ab6a7475c338bdf101bc6461930aaa7a012a02cf93f347c207 dd0fc1a88180fde8367bec7086f99294f36b8332f12994293139ed532d2ebbac 5c3f190571645c4641dcff2c07a4c3ab9acad06aa9607350a385729d8d6139f1 323c3a91be60ebc3e06e942bad04899a15911cea23269e43d07829164b2ce5d4 880425fee707e9f42e0b8d60119ed639b1ad506ea29877d126bdebce379cd229 e5d2de8ae98579bfb940290f60e59a502b3065345aaf765456387989c0488b20 2e0e43776e2e1a37d882a1b2ebb7d337ee88950177e43831dae645a367824feb b5969636eec376ad6c3ece2202b1722219955638e09b6f96d4cfc0598d3b1890 1660536f448b8b9f086ce9ea3ce4e9deefc59a76711ea53ee6d8f08fc8c1bb99 65feba2c971c214e71303ad2e0fbf62b45ebcaa784cbf3d0dab62786cb4c0469 53ac2b231c23d41234e55b1f7ed89f86234f785adbbe820959655d7b019d7df9 33c10b77e1da9f0679023d55fb3057879d15609db9c1d46ee5c3ff1240a3d052 5faea1650cac0f3ffd2dc1fb220182095a46e34158967d37c2a942e85e2ca97b 62d4ec87ed21f0d15cb769b0b2a5577cab41fc2cdb1e7e796c5bdff09264dd9a 534a4a5bff2609a2d6e088cb87465c08c2d69c6aaa7d2ffcbcd491274b8505f1 5eab4c61baa67ae2838a36c2e6ff0476a8f2117b96a7027b830c8cb46ce78efc 0af4c52a1d13e4132a1843ce7727abcf0ddd4d1ca6a4b17cdf599ec3f355c241 d4861088161fc72b9922abf933b4ea664a807105ec1eab4a173253aa60bfe6d7 3d296af7f29c0425655bd1cc0be48fe4aba52ee6760a89e805ca2589f4ef4d77 f235d2e044c2f7814e6bbcd835b9fd9f10f227dacfb9396185ec2013e7df4db4 4130f49fa81a699a667cafdbd6d1f6e781edd686c947eb8ae27134f6dc2c43d7 0a8555a71868749be8c905ed53296ce335af50a9262772b5e154ad3f9c35c2e4 5dbfa033676b5caacfae902734ce462cd871181eefbe299250ca8ac7e139719e 20fcba222f74dd68aaeb1f0ad30cdf702a828ee164a182b30d05d600c35b72d9 912adea5339c73cb4a777a3e9f98bf3cb08da6622c9dd3b4cc9b083cb03d10a2 03926e3da998f32ad898b640bd15cf145768f9e849e6f18d81350234254c424e 16971f9706d70ac4925651c7c8719b9d77aff63e4c0a618129efc32c2c46b989 6917c0f9eafefe42e33e791b75a7e503ff8b081bc10a98449e4076787dfc6c16 c7c9bfa9ffcd8fb6a2afe656f510c406ddc58ebff48ce1d0fd3fad951b46a36e b9fe48bda9a6c8787981a24f8bbc723a6f6aa80cab5fa53481937382f3c6ce85 f3fbf4481f30fd840f35568746f54be49eb92b2c9ac95597a7760abb171cb54b 6366d59b573d50fd23ff650923c4a8c1c918518a02d0a56f12c23533c45f439d 3fcaa3038e365b6ab0b121e2cd319c56b74e37381943a0da0e8dce407087cdb8 bf70c6f3a8e913f526ec57eeec50e1306f7b34b037915b7a1cf2968cc46acc58 0352f3e338261d98895df4c7b7a76b296485b2290c72bce56603351d167d0601 52b871429833e1dee348263844efb531f6a3fcd321f88dc8a876caaee912cedd 5db2ce9acd50f96d566e8d139f6490abf2bbf7a9293b876eeb4598fd2c37c515 3169a6dbcce684e2c5a2f166996b58ffa673df6e58b8edf2bdf3e66271c8c69e d871d76171504597bbda387689e12e7a5e354c360ff135f4df231cec68c761af d1f963b88672f3676a7da1580262ba0d4f367cc57a94b551754c20f77a670c43 76d9e2a2ff313f5b91cc67aab1127122baee1c3efbae1087e58a25bc5f1eb065 8c104da0e66ef6384663309aaf8fb49f549f2785d835eec620b265f8aa11d9f0 c494c878e28284539419612616d964ab9224cbe27e57f42293d91d02d684e3db 08701ed7975bf4f5688c2724d27ab497764200ad6f4dc53d3cc03b170378ced0 604b53f87d6c070bf387e80c70a6df8d272fa3fc143148d41f13e59d52ab1f13 0a8cae96e25e85c612b0736fe886f9b124ad70ec425bc2ec1a8a4135b25436ba 8459ff264a2c81c68a34c4ee6bc109d141ad28b96037d34ff112322a4c853739 68445a37a9943a267a8b2100fba2678353d6ec88844505ccbba659e586c7a105 29686c933cec1e274467e2dae264625ae6f754824bb7f550bc9c3131f625562c d973ad5a80c3d7468a9c392db4166857ed32b5d61cd6755766ba8922156dada3 f5a57dfae488d9dfe260b32460a1d947fb5af58ceaf2fb0139bc08b4bb79a966 2ebc1b6cf543e2cb3f22d9a5b54b6676bb71dde98df7532f8791297734e44fdd 6dbd507ca7cecea861f9cf704b3c5c37f5bd5392886a8c2562088892b7703fa5 89f0a67bc595ab8bce02c2f95f9292ad06e1868207e809c76bd16f0cab800c06 d81201d0fc19977e51104438a5b9cba861f4da20cea3ae9183edf16ab11d98f8 9d52cb4febf3342c34dcc8198dcaf453458be3699ab47dc08616aa7f18daa7fa 9a927c37a31b80975c5c5467f112b61478c9493c046281046443525358a5acb0 6cda1e81667f869940401f05a55c8dea94dbdf3ceffb93b5f320a6462cfea44d 745538dea8ed9aec4466e67a9d0aecf9e7026ff16a792d1d6f306e8b67d3f34c 13acadb3541e75af50e02d5be56c2238b93d8f154ce5514be1558e6ee59a1432","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","apt","malware","cisco-talos-antivirus","cisco-talos-malware-protection","cisco-talos-network-intrusion-prevention","cisco-talos-web-filtering","geo:inferred"],"relatedCves":["CVE-2025-2492"],"titleFingerprint":"7810-building-continues-malware-networks-orb-uat-using","countryCodes":["CN","HK"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/uat-7810/","type":"report","title":"Cisco Talos: UAT-7810 continues building ORB networks using new malware"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-07T10:00:05.000Z","addedAt":"2026-07-29T20:53:06.718Z","updatedAt":"2026-07-29T20:53:06.718Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]}],"pagination":{"page":1,"limit":20,"total":3,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T22:35:04.630Z","durationMs":55,"filters":{"search":null,"severity":[],"type":[],"country":["HK"],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}