{"success":true,"data":{"threats":[{"id":"9dc6b0cd-8c8e-46b7-937a-9e4c2a7c1e60","slug":"talos-give-yourself-room-to-be-human-8c885f05","externalId":"6abd6c72bff6790001c729f7","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Give yourself room to be human","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xa0; Fall is officially here in Maryland, and I can&#x2019;t be more relieved. I flourish in 50 degree weather, where it feels natural to burrow under blankets, knit sweaters, and listen to an audiobook.&#xa0; Beyond that, though, can I say that I&#x2019;m glad fall is here because the end of summer has been a bit of a shitshow? I&#x2019;m allowed to curse on here, right?&#xa0; Without going into too much detail, my uncle was diagnosed with a rare cancer, and my family decided we were going to fly out&#xa0;to spend a week with him. I was determined to find a way to make it work, but on top of all of the emotions, my mind was racing with trying to figure out how to request the time off and get coverage for the tasks I&#x2019;d be missing.&#xa0; I was anxious to ask, but my manager&#x2019;s response to me requesting the week off was: &#x201c;Family always, always comes first at Talos. You spend as much time with your family as you need. Don&#x2019;t worry, we&#x2019;ll work everything out. We have your back.&#x201d; I knew I was in such a fortunate position to have that kind of support. Yet, even with the explicit encouragement to step away, there was still a lingering weight on my shoulders that I couldn&apos;t quite set down.&#xa0; LinkedIn might be an awful, artificial place, but occasionally I&#x2019;ll find a non-AI-generated think piece or quote that sticks with me. On a recent post, I read, &#x201c;We&#x2019;d all be better off if we gave each other a little more room to be human here without worrying it makes us look less capable.&#x201d;&#xa0; Okay, ouch! That described the unsettled feeling to a T. Ever since I was laid off at my previous company, my trauma response has insisted I prove myself, make myself &#x201c;indispensable&#x201d; and capable of taking on any challenges thrown my way. I&apos;m sure if you&apos;ve been through a layoff, you can relate.&#xa0; If you&#x2019;re scared of your team perceiving you as&#xa0;less capable and more dispensable, please hear this: You are not a machine, and your value to your team isn&apos;t defined by how much personal or professional weight you take on without a break. It&apos;s so easy&#xa0;to extend grace to others, to insist that they spend time with their ill family members, but we have to extend the same grace to ourselves.&#xa0; If your team is great, they&#x2019;ll want you at your best, not just your most productive, so you can fight the good fight. Don&apos;t let this fear stop you from taking the time you need. Life is worth living now, and we&#x2019;re better at what we do when we&#x2019;re well in all aspects of life. The one big thing &#xa0;For Cybersecurity Awareness Month, Talos is sharing crowdsourced strategies from our researchers to help you master &#x201c;The Fine Art of Frustrating the Adversary.&#x201d; By deploying deception techniques, behavioral detections, and strict controls over legitimate tools, defenders can strip away an attacker&apos;s advantages. The goal is to make every alternative slower, less stealthy, and significantly more expensive for the threat actor. Ultimately, we want to force them to make mistakes or give up entirely.&#xa0; Why do I care?&#xa0;Threat actors rely on predictable environments, dual-use tools, and manufactured urgency to execute operations at scale. If defenders rely solely on tool-specific detections, adversaries can easily pivot by simply swapping out a payload. Shifting to behavior-based detections and introducing friction, like honeypots or strict AI boundaries, exploits the fact that attackers have rigid end goals. This approach slows down their operations and gives defenders earlier opportunities to interrupt the attack chain.&#xa0; So now what?&#xa0;Start by allowlisting approved remote monitoring and management (RMM) tools and blocking unauthorized ones to prevent dual-use abuse. Build resilient behavioral analytics that target underlying techniques rather than specific malware. Consider deploying deception tactics like fake employee profiles or false infrastructure. Ensure any AI agents in your environment have identifiable, short-lived credentials and strict network boundaries. And, of course, explore the blog to dive deeper into these strategies.&#xa0; Top security headlines of the week&#xa0;South Africa seeks help after cyber attack targets air traffic control&#xa0; The South African state-owned company that provides air traffic control and weather operations for approximately 10% of the world&apos;s airspace discovered ransomware-linked malware in an OT network.&#xa0;(Dark Reading)&#xa0; Automated AI agent used to breach cybersecurity nonprofit DIVD&#xa0; The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyber attack that the organization described as &#x201c;loud and very, very messy.&#x201d; Evidence uncovered during the ongoing investigation indicates the attacker exploited a vulnerability, but the attack&apos;s purpose and impact remain unclear at this stage. (Bleeping Computer) Citrix confirms 2 NetScaler zero-days after admins pulled the plug&#xa0; Citrix rushed out patches for two critical NetScaler zero-day vulnerabilities that have been exploited in the wild. The advisory&#xa0;covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway. (SecurityWeek)&#xa0; Pentagon personnel agency data breach impacts 3 million people&#xa0; The US Defense Manpower Data Center (DMDC), which maintains personnel records for the Pentagon, has started notifying people that their personal information was exposed.&#xa0;Unauthorized users had access to one of its file-sharing servers for roughly nine months. (SecurityWeek)&#xa0; TeamViewer urges users to patch severe flaws &#x201c;as soon as possible&#x201d;&#xa0; Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. (Bleeping Computer)&#xa0; Cisco&#x2019;s Relentless Defense report is available now&#xa0; Cisco asked 8,000 security leaders from across the globe how they&#x2019;re coping with a threat landscape being reshaped by AI, including whether their processes can keep pace with AI&#x2019;s ability to surface thousands of vulnerabilities at once, and whether they&#x2019;re confident staying ahead of the volume of new threats being discovered. (Cisco)&#xa0; Can&#x2019;t get enough Talos?&#xa0;China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor&#xa0; Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as &#x201c;Antino&#x201d; in developer artifacts.&#xa0; Securing the keys to the kingdom: Announcing Executive Threat Detection&#xa0; For a sophisticated threat actor, an executive is not only a high-ranking employee, but also a high-yield target. Talos IR&#x2019;s new service offers protection for up to 10 principals, with monthly custom threat hunts and reports relevant to your organization&#x2019;s most high-value IT assets.&#xa0; Beers with Talos: Your AI malware experiments are showing&#xa0; Adversaries are experimenting with AI-integrated malware, and today&apos;s guest, Talos researcher Ryan Fetterman, has been looking at their working notes.&#xa0; Upcoming events where you can find Talos&#xa0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xa0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xa0;SecurityOnion Conference (Oct. 23) Augusta, GA&#xa0;BsidesAugusta (Oct. 24) Augusta, GA&#xa0;SAINTCON (Oct. 26 &#x2013; 30) Provo, UT&#xa0;Most prevalent malware files from Talos telemetry over the past week&#xa0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xa0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xa0; Example Filename: sample.exe &#xa0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xa0; SHA256: 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974&#xa0; MD5: aac3165ece2959f39ff98334618d10d9 &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974&#xa0; Example Filename: d4aa3e7010220ad1b458fac17039c274_63_Exe.exe &#xa0; Detection Name: W32.Injector:Gen.21ie.1201&#xa0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xa0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xa0; Example Filename: tmp00055df5.dll &#xa0; Detection Name: Auto.90B145.282358.in02&#xa0; SHA256: 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8&#xa0; MD5: d65c7b544a97b0c3f2773b5fcc57d30e &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8&#xa0; Example Filename: f_006048.exe &#xa0; Detection Name: W32.540080FEA9-95.SBX.TG&#xa0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; Example Filename: SECOH-QAD.exe &#xa0; Detection Name: W32.9896A6FCB9-95.SBX.TG","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":"give-human-room-yourself","countryCodes":["CN","ES","IN","KH","NL","PH","TW","ZA"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/give-yourself-room-to-be-human/","type":"report","title":"Cisco Talos: Give yourself room to be human"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T18:00:52.000Z","addedAt":"2026-10-01T18:52:59.295Z","updatedAt":"2026-10-01T18:52:59.295Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"b03974dc-16e5-453f-8f31-6bf2028276b9","slug":"talos-china-nexus-uat-11587-targets-government-and-policy-94d4e2d7","externalId":"6ab6d674db2bd20001a36150","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor","description":"Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as &#x201c;Antino&#x201d; in developer artifacts.&#xa0;Talos first observed UAT-11587 activity in September 2025.&#xa0;By July 2026, Talos had identified at least 16 affected or targeted institutional environments across eight Asian countries.&#xa0;Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence. Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.&#xa0;Talos identified a recurring delivery branch that began with spear-phishing emails and tailored decoy documents, followed by a five-stage infection chain. The actor relied heavily on Cloudflare infrastructure for delivery, execution tracking, and payload staging.&#xa0;Based on the development, preparation-environment, and targeting indicators detailed in this report, Talos assesses with high confidence that UAT-11587 is China-nexus.Overview&#xa0;Talos first identified UAT-11587&#x2019;s campaign while investigating a spear-phishing campaign directed at Taiwan&apos;s academic, think tank, and civil society policy community in March 2026. The message recreated Gmail&apos;s attachment interface and directed the target into a cloud-hosted, multi-stage infection chain.&#xa0; Across this activity, our researchers assessed that the actor used several delivery methods, loader families, and post-compromise tools. One recurring final-stage payload was a custom Rust backdoor that Talos tracks as Antino. Antino communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, rather than depending on a conspicuous dedicated command server.&#xa0; Further investigation showed that the activity extended beyond the initial Taiwan operation. Talos subsequently identified confirmed or probable affected government and security environments across multiple Asian countries, alongside additional regional targeting supported by lure content.&#xa0;&#xa0; While this report was being prepared, Symantec published research on an activity set it tracks as Jewelbug. Talos identified overlaps between UAT-11587 and the Antino-related espionage activity attributed to Jewelbug. Although Symantec reported that Jewelbug conducted both espionage and cryptocurrency fraud, it assessed that &#x201c;the SEO business supplied access, delivery and infrastructure into the espionage operation, rather than that one person performed both roles.&#x201d; Talos could not independently verify a connection between the espionage campaign and Jewelbug&#x2019;s financially motivated activity. We therefore track UAT-11587 as a separate activity set.&#xa0; Who is UAT-11587?&#xa0;Talos assesses with high confidence that UAT-11587 is a China-nexus actor, based on the totality of corroborating technical and operational evidence, rather than any single indicator. The indicators discussed below are selected examples of the broader evidence supporting this assessment.&#xa0; Evidence supporting the attribution assessment&#xa0;Decoy document metadata provides several preparation-environment clues. A Taiwan-focused decoy contains the zh-CN language tag, the Simplified Chinese author value &#x672a;&#x5b9a;&#x4e49; (&#x201c;undefined&#x201d;), and an explicit +08:00 creation timestamp. Both recovered spear-phishing messages also contain +08:00 date headers. UTC+8 alone is not geographically distinctive because it is used across mainland China, Taiwan, Hong Kong, Singapore, and other locations. However, the combination of the +08:00 offset, the zh-CN language tag and Simplified Chinese metadata is more consistent with a mainland Chinese environment than with Taiwan or Hong Kong, where Traditional Chinese predominates.&#xa0; Figure 1. Decoy metadata.&#xa0;The campaign&#x2019;s lure theme and targeting provide additional contextual support. Its lures and observed targets include Taiwanese political, legislative, civil defense, and policy research subjects, together with regional government, maritime, diplomatic, and security themes. This collection focus is consistent with China-nexus actor interests.&#xa0;&#xa0; Another supporting indicator appears in Antino&#x2019;s development artifacts. Ten distinct Antino build outputs contain Cargo registry paths referencing rsproxy.cn, a Rust package mirror intended to improve dependency downloads within mainland China. The service&#x2019;s public accessibility does not reveal the developer&#x2019;s location, but its repeated use suggests reliance on a China-focused Rust mirror.&#xa0; During our investigation, Talos also identified a JavaScript downloader associated with UAT-11587 that referenced &#x201c;d32tpl7xt7175h[.]cloudfront[.]net&#x201d;, the same CloudFront distribution previously reported by Arctic Wolf in China-nexus UNC6384 delivery activity. This shared infrastructure suggests possible delivery-layer overlap. However, because cloud infrastructure can be reused and the campaigns employed different core malware and command-and-control (C2) architectures, Talos assesses this relationship with low confidence and continues to track UAT-11587 as a separate activity cluster.&#xa0;&#xa0; Victimology&#xa0;UAT-11587 primarily targeted public-sector and national-security-adjacent organizations across Asia. By July 2026, Talos had identified at least 10 confirmed and five probable affected institutional environments, plus one additional intended target. Our investigation reveals approximately 350 compromised endpoints across eight countries.&#xa0; &#xa0;The affected or targeted sectors included:&#xa0; Defense, military, and national security&#xa0;Executive government and central public administration&#xa0;Foreign affairs and diplomatic services&#xa0;Justice, law enforcement, border security, and interior security&#xa0;Legislative and parliamentary institutions&#xa0;Government IT and shared e-government services&#xa0;Think tanks, universities, and research institutions&#xa0;Civil society, human rights, and public policy organizations&#xa0;&#xa0;Based on the available evidence, Talos assesses with moderate-to-high confidence that the campaign targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria.&#xa0; Figure 2. Victimology mapBased on its sustained targeting of government and national security-adjacent organizations, tailored political and diplomatic lures, and capabilities supporting persistent access and information collection, Talos assesses with moderate confidence that UAT-11587 is conducting intelligence gathering operation. &#xa0; Campaign timeline&#xa0;Talos observed UAT-11587 activity from September 2025 through July 2026. The earliest reviewed activity, from September through November 2025, used Philippines-themed lures and direct email attachment delivery. In January 2026, the actor conducted two additional Philippines-focused HTML application (HTA) campaigns and began using a broader set of policy and geopolitical lures alongside a standalone fake installer delivery branch. Activity accelerated between March and early June, with closely timed operations involving the Philippines and Taiwan, followed by activity affecting or targeting environments in Cambodia, Myanmar, Syria, Pakistan, and Thailand. The largest concentrated wave occurred on June 8 and 9, when Talos identified around 57 newly observed endpoints associated with India.&#xa0; Figure 3. Timeline of UAT-11587 campaign activity.Spear-phishing delivery and sender spoofing&#xa0;UAT-11587, like many targeted intrusion sets, relies on spear-phishing emails to deliver its infection chain. The social engineering themes used in these emails suggest the threat actor possessed detailed prior knowledge of their target organizations. This targeting precision is particularly apparent in the Taiwan campaigns, where lure content was carefully aligned with the operational and institutional context of each target.&#xa0; Abusing sender-domain misalignment to spoof trusted senders&#xa0;To make its spear-phishing emails appear more credible, UAT-11587 spoofed sender identities trusted by the intended recipients. The actor exploited the distinction between the SMTP envelope sender and the visible From header. Messages were sent through Migadu using the attacker-controlled &#x201c;osc-cdn[.]com&#x201d; domain as the RFC5321 envelope sender, while the RFC5322 From header displayed the identity of the organization being impersonated.&#xa0; &#xa0;SPF passed because Migadu&#x2019;s sending infrastructure was authorized to send email on behalf of &#x201c;osc-cdn[.]com&#x201d;. However, this result authenticated only the envelope-sender domain, not the sender displayed to the recipient. DMARC detected that the envelope and visible sender domains were not aligned and returned a failure. In the reviewed message, the displayed domain used a non-enforcing p=none policy, which requested monitoring rather than quarantine or rejection. The receiving provider therefore accepted the message, allowing the spoofed email to be successfully delivered to the recipient&#x2019;s inbox despite the DMARC failure.&#xa0;&#xa0; Figure 4. The spoofed email passed SPF.&#xa0;Gmail attachment widget cloning&#xa0;Another social engineering technique used for initial access in this campaign was the closely replicated reconstruction of Gmail&#x2019;s native attachment preview widget inside the email HTML body. The actor replicated the styling of Gmail&#x2019;s attachment card using four inline PNG images embedded as Base64-encoded MIME parts. The entire attachment card was wrapped in an anchor tag pointing to an attacker-controlled URL. These links use Cloudflare Pages URLs with the pattern shown below. The ?m= parameter carries a target identifier and therefore permits per-recipient logging at the delivery service //my-<project>.pages.dev/File_download?m=<target-identifier>. The actor used a protocol-relative URL beginning with //, which may be overlooked by security tools that extract only fully qualified HTTP or HTTPS URLs.&#xa0; When a Gmail user opens the email in a browser, Gmail&#x2019;s renderer faithfully displays the attacker-controlled HTML, producing a fake attachment widget that is visually indistinguishable from a legitimate Gmail attachment preview.&#xa0; Figure 5. Spear-phishing email sample.Figure 6. HTML code in the email with link to download malware.Tailored lures and decoy documents&#xa0;Our analysis recovered three decoy documents during separate UAT-11587 operations. The first decoy described a workshop focused on the &#x201c;Taiwan Information Warfare.&#x201d; The document referenced a 2025 TikTok study and discussed perceived public knowledge gaps concerning cross-strait issues and information manipulation.&#xa0;&#xa0; Figure 7. Decoy document recovered from Taiwan-targeting campaign.&#xa0;The second decoy, titled &#x201c;&#x7acb;&#x6cd5;&#x59d4;&#x54e1;&#x884c;&#x4f7f;&#x8077;&#x52d9;&#x652f;&#x9818;&#x4e4b;&#x5404;&#x9805;&#x8cbb;&#x7528;&#x5fb5;&#x514d;&#x7a05;&#x539f;&#x5247;&#x201d; (&#x201c;Principles governing the taxation of expenses received by legislators in performing their duties&#x201d;), used a narrower administrative pretext. It describes the income tax treatment of legislators&#x2019; remuneration, overseas travel, and expenses incurred while performing legislative duties. The document exactly reproduces a public Taiwan Ministry of Finance ruling to make the decoy appear credible. Its subject strongly suggests that it was prepared for members of Taiwan&apos;s public sector.&#xa0; Figure 8. Taiwan-focused decoy document.&#xa0;Outside Taiwan, Talos recovered a two-page decoy titled &#x201c;CSIS Indo-Pacific Forecast 2026 (Event Details).&#x201d; The document borrowed the framing of a legitimate event and referenced real experts, presenting an agenda focused on regional alliances, gray-zone security, demographic trends, and human security. The subject matter would plausibly appeal to government, diplomatic, think tank, academic, and security policy audiences across the Indo-Pacific, including readers focused on India.&#xa0; Figure 9. Indo-Pacific policy-themed decoy document.&#xa0;Beyond the recovered decoys, file names of malicious executables, HTA files, and WSF stagers revealed additional themes spanning maritime policy, foreign affairs, diplomatic events, human rights, government administration, and technology research.&#xa0; One lure shows how the actor exploited current geopolitical developments. &#x201c;Trump&#x2019;s Former Russia Adviser Claims Moscow Offered US Free Rein in Venezuela in Exchange for Ukraine&#x201d; closely paraphrased an Associated Press report, with two related samples appearing on VirusTotal two days later.&#xa0;&#xa0; Together, these examples show the actor using both news-style headlines and official-sounding documents to target audiences interested in foreign affairs, international security, and government policy.&#xa0; The table below lists the likely audience for each lure. Where recipient details or decoy content were unavailable, assessments are based solely on file names and subject matter and do not confirm delivery or compromise.&#xa0; Lure or decoy title&#xa0; Potential target or audience&#xa0; 115&#x5e74;&#x5ea6;&#x85aa;&#x8cc7;&#x6240;&#x5f97;&#x6263;&#x7e73;&#x7a05;&#x984d;&#x8868;&#x8aaa;&#x660e; (Instructions for the 2026 Salary Income Tax Withholding Table)&#xa0; Taiwanese think tank&#xa0; Resolution on the Updated Chart of Bajo de Masinloc&#xa0; Likely Philippine public sector&#xa0; Trump&apos;s Former Russia Adviser Claims Moscow Offered US Free Rein in Venezuela in Exchange for Ukraine&#xa0; Foreign-policy, government, research, or media audiences interested in the topic.&#xa0; CrossBorder_Repression_Seminar_Agenda&#xa0; Likely human-rights, civil-society, diaspora, academic, or policy communities.&#xa0; the May 27 inauguration of the TPiE&#xa0; Regional political and civil-society audiences&#xa0; Tehran_Bilateral_Summit_Proceedings_May2026&#xa0; Likely diplomatic, foreign-affairs, or policy audiences following a Tehran-based bilateral meeting.&#xa0; Items likely to be considered in the next Cabinet meeting.T11065885611.doc.exe&#xa0; &#xa0;Indian government audiences&#xa0; UO -C-DAC (1)&#xa0; Indian government technology and research audiences&#xa0; The infection chain&#xa0;In the reviewed spear-phishing operations, the actor uses a five-stage infection chain that begins with an HTA stager. Later stages abuse unsafe BinaryFormatter deserialization and gadget chains in standard .NET assemblies to load and execute the final payload.&#xa0; Figure 10. Antino backdoor infection chain.Stage 1: HTA and WSF Stager&#xa0;The &#x201c;my-<project>.page[.]dev&#x201d; Cloudflare URL in the spear-phishing emails leads to the download of an HTA file that was executed by mshta.exe. It hides and resizes its window, emits a tracking request to an invariant Cloudflare Pages beacon, and imports the next JavaScript stage from a cloud-hosted location. The same general template appears across multiple campaign variants:&#xa0; Figure 11. HTA stager.&#xa0;The actor uses two cloud services to deliver the second-stage JavaScript:&#xa0; Cloudflare R2: &#x201c;pub-<32-character hexadecimal identifier>[.]r2[.]dev&#x201d;&#xa0;Amazon CloudFront: &#x201c;d2nq35tel3ucuo[.]cloudfront[.]net&#x201d;&#xa0;The fixed Cloudflare Pages hostname &#x201c;oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev&#x201d; appears across multiple reviewed HTA variants. A hidden image causes mshta.exe to send a request containing the lure title in the URL path and ?track in the query string. This could allow the operator to correlate HTA execution with a particular lure for campaign tracking.&#xa0;&#xa0; Talos also observed WSF stagers that perform the same role through Windows Script Host. They send an HTTP HEAD request to the tracking host name with the lure title in the URL path, then load the next JavaScript stage from Cloudflare R2. Although paired HTA and WSF samples use different R2 objects and obfuscated loaders, both lead to the same infection chain.&#xa0;&#xa0; Figure 12. WSF stager script.Stage 2: HTA-hosted JScript downloader and decryptor&#xa0;The Stage 2 component is HTA-hosted Microsoft JScript, delivered from Cloudflare R2 and loaded in-process by mshta.exe through the HTA stager. It acts as a downloader and decryptor that prepares the next stage in-memory .NET deserialization chain. The script retrieves three encrypted resources from the cloud-hosted delivery infrastructure:&#xa0; Encrypted JavaScript orchestrator (.js file)&#xa0;Encrypted .NET serialized gadget resource 1 (.txt file)&#xa0;Encrypted .NET serialized gadget resource 2 (.txt file)&#xa0;After downloading the files, the script applies custom Base64 decoding and decrypts each response with RC4 using an embedded key. It then executes the decrypted JScript orchestrator in memory to initiate the .NET 4.x deserialization chain.&#xa0; Figure 13. HTA-hosted JScript downloader and decryptor.&#xa0;Stage 3: .NET BinaryFormatter deserialization chain&#xa0;The three files downloaded from Cloudflare R2 or Amazon CloudFront are the JScript orchestrator and two serialized .NET gadget resources. The threat actor leverages a scripted .NET deserialization technique in which JScript instantiates COM-visible .NET classes and passes attacker-controlled serialized data into BinaryFormatter. During deserialization, the embedded gadget chain drives execution, allowing the malware to load and execute an embedded .NET assembly, the next-stage &#x201c;TestAssembly.dll&#x201d;, inside the script host process, mshta.exe.&#xa0; Figure 14. JScript orchestrator.&#xa0;The JScript orchestrator deserializes the two resources in sequence. It first attempts to deserialize stage_1, which appears designed to disable a .NET security check introduced to block ActivitySurrogateSelector-based deserialization gadget chains. The code wraps this operation in a try/catch block and proceeds to stage_2 when an exception occurs, suggesting the actor anticipated differences in .NET versions, patch levels, or assembly availability across target systems. The two-call behavior observed in stage_1 appears intended to improve compatibility across different .NET patch levels.&#xa0;&#xa0; The second serialized resource, stage_2, uses the System.Windows.Forms.AxHost+State deserialization gadget in combination with an ActivitySurrogateSelector gadget chain. This technique substitutes a surrogate object during deserialization to drive code execution. In this case, the gadget chain loads the embedded PE file, &#x201c;TestAssembly.dll&#x201d;, directly into memory and executes it inside mshta.exe.&#xa0; Stage 4: &#x201c;TestAssembly.dll&#x201d; downloader and launcher&#xa0;&#x201c;TestAssembly.dll&#x201d; is a small .NET downloader and launcher that Stage 3 loads directly into mshta.exe through the BinaryFormatter deserialization chain. It downloads a lure-specific decoy document and a three-file DLL-sideloading bundle from cloud-hosted infrastructure. It opens the decoy, writes the bundle to a writable staging directory, and launches the Microsoft-signed &#x201c;GatherOsState.exe&#x201d;, which sideloads &#x201c;slc.dll&#x201d;, the Antino backdoor.&#xa0; The table below shows the files retrieved during one Taiwan-targeting campaign. Note that the actor uses randomized nonstandard extensions (.luy, .pzs, .syk) that remove obvious executable/DLL filename signaling.&#xa0;&#xa0; CDN URL&#xa0; Actual Content&#xa0; Description&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6Z[&#x2026;].pdf&#xa0; Lure-specific PDF&#xa0; Decoy document opened for the victim&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6ZGatherOsState.exe.luy&#xa0; GatherOsState.exe (legitimate signed binary)&#xa0; Legitimate signed binary that loads slc.dll&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6Zslc.dll.pzs&#xa0; slc.dll (Antino C2 implant)&#xa0; &#xa0;Antino backdoor&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6ZOsGather.dat.syk&#xa0; OsGather.dat&#xa0;&#xa0; Calculator decoy PE&#xa0; All the &#x201c;TestAssembly.dll&#x201d; downloader builds recovered in this investigation share the AssemblyAttribute GUID b2b3adb0-1669-4b94-86cb-6dd682ddbea3. This is a useful tooling-level detection marker.&#xa0;&#xa0;&#xa0; Figure 15. .NET assembly metadata for the TestAssembly component.&#xa0;Stage 5: Signed-host DLL sideloading Antino backdoor&#xa0;The downloaded &#x201c;GatherOsState.exe&#x201d; is a legitimate Microsoft-signed Windows Assessment and Deployment Kit (ADK) binary that was abused for DLL sideloading. When executed, it loads &#x201c;slc.dll&#x201d; from its local directory. The attacker placed the Antino backdoor file slc.dll alongside the signed executable, which then calls the DLL&#x2019;s SLOpen export to start Antino.&#xa0; C2 infrastructure&#xa0;Beyond email delivery, UAT-11587 relied extensively on Cloudflare throughout the infection chain. Cloudflare Pages hosted malicious HTA and WSF files and a separate execution-tracking endpoint, while Cloudflare R2 stored encoded loader stages, decoy documents, and payload components. UAT-11587 also used Amazon CloudFront to deliver additional scripts and decoy content. This architecture placed much of the infection chain within widely used cloud services and ordinary HTTPS traffic.&#xa0; We also identified software-themed domains that directly hosted standalone Antino executables. The domain &#x201c;microsoft-flash[.]com&#x201d;, registered shortly before its use, served Antino samples from &#x201c;https://microsoft-flash[.]com/download/flashcenter_pp_ax_install_en.exe&#x201d;. Similarly, &#x201c;wps-cn[.]com&#x201d; delivered a related Antino build from &#x201c;https://www.wps-cn[.]com/downloads/flashcenter_pp_ax_install_en.exe&#x201d;. The choice of &#x201c;wps-cn[.]com&#x201d; may also indicate that the delivery site was designed to appeal to Chinese-speaking users, particularly those in mainland China.&#xa0; While the infection chain relied heavily on Cloudflare, Antino itself used Microsoft 365 for post-compromise C2. The &#x201c;Dead-drop C2 communication&#x201d; section explains this channel in more detail.&#xa0; The Antino backdoor&#xa0;Antino is a , Rust-compiled Windows backdoor observed in both 32-bit and 64-bit builds. Talos named the malware after identifying AntinoApp in its Windows application manifest and repeated antino directory names in PDB and Rust source paths across multiple variants. It supports host reconnaissance, command execution, persistence, and Microsoft Graph-based C2, using Outlook for command exchange and OneDrive for heartbeat and file transfer.&#xa0; Figure 16. The Windows application manifest identifies the program as AntinoApp.&#xa0; D:\\a\\antino\\antino\\target\\x86_64-pc-windows msvc\\release\\deps\\slc_template.pdb&#xa0; D:\\a\\antino\\antino\\target\\x86_64-pc-windows-msvc\\release\\deps\\antino_client_template.pdb D:\\a\\antino\\antino\\target\\i686-pc-windows-msvc\\release\\deps\\antino_client_template.pdb D:\\a\\antino\\antino\\client\\src\\core.rs D:\\a\\antino\\antino\\client\\src\\signaller\\mod.rs D:\\a\\antino\\antino\\client\\src\\artillery\\run.rs D:\\a\\antino\\antino\\client\\src\\config\\mod.rs D:\\a\\antino\\antino\\shared\\src\\command_client.rs D:\\a\\antino\\antino\\shared\\src\\command\\registry.rs D:\\a\\antino\\antino\\shared\\src\\command\\add_to_run.rs D:\\a\\antino\\antino\\shared\\src\\command\\cmd.rs D:\\a\\antino\\antino\\shared\\src\\command\\download_file.rs D:\\a\\antino\\antino\\shared\\src\\command\\execute_program.rs D:\\a\\antino\\antino\\shared\\src\\command\\exit.rs D:\\a\\antino\\antino\\shared\\src\\command\\list_files.rs D:\\a\\antino\\antino\\shared\\src\\command\\load.rs D:\\a\\antino\\antino\\shared\\src\\command\\ps.rs D:\\a\\antino\\antino\\shared\\src\\command\\system_info.rs D:\\a\\antino\\antino\\shared\\src\\command\\upload_file.rs The &#x201c;D:\\a\\antino\\antino\\...&#x201d; paths follow the standard GitHub Actions Windows workspace structure, &#x201c;D:\\a\\<repository>\\<repository>\\...&#x201d;. This suggests that the reviewed CI variants were compiled on GitHub-hosted Windows runners.&#xa0; The backdoor was observed in both standalone executable and DLL forms. Our analysis observed two generations of Antino, distinguished by consistent differences in their underlying code and Rust build environment. The clearest implementation differences involve session-ID generation and registration and heartbeat behavior.&#xa0;&#xa0;&#xa0; Characteristic&#xa0; Antino Gen1&#xa0; Antino Gen2&#xa0; Observed build period&#xa0; October 2025&#xa0; December 2025 to January 2026&#xa0; Application identity&#xa0; No AntinoApp manifest in the reviewed builds&#xa0; Uses the AntinoApp application manifest&#xa0; Session identifier&#xa0; XOR- and Base64-encodes the process ID, computer name, username and platform.&#xa0; Generates a random UUID v4 containing no host-derived information&#xa0; Registration and heartbeat&#xa0; Classic builds use sendsession and heartbeat email drafts; an early DLL already supports OneDrive heartbeats&#xa0; Stores JSON heartbeat objects under &#x201c;/antino/heartbeats/<session_id>.json&#x201d;; the heartbeat also registers the implant&#xa0; Dead-drop C2 communication&#xa0;Antino communicates exclusively through Microsoft 365, using the Microsoft Graph API to interact with Outlook and OneDrive as dead-drop C2 channels. Both Antino generations use broadly similar Microsoft 365-based C2 workflows. This design allows Antino&#x2019;s C2 traffic to blend into legitimate Microsoft application synchronization at the network layer. Outbound connections terminate at &#x201c;graph.microsoft.com&#x201d; and &#x201c;login.microsoftonline.com&#x201d;, both of which are widely trusted and commonly allowed in enterprise environments.&#xa0;&#xa0; The Antino Gen2 implant authenticates to Microsoft Graph using the OAuth 2.0 client-credentials flow. This authentication method allows the registered Entra ID application to access the configured Outlook mailbox and OneDrive resources without requiring an interactive user sign-in.&#xa0; The Antino implant uses two distinct mechanisms for C2 communication, implemented in separate modules:&#xa0; Mechanism 1: OneDrive file-based communication&#xa0; The Antino backdoor uses the threat actor&#x2019;s OneDrive for registration and file-based communication. The OneDrive folder used for communication includes three folder paths:&#xa0; Path&#xa0; Direction&#xa0; Purpose&#xa0; /antino/heartbeats/{id}.json&#xa0; Antino upload&#xa0;&#xa0; Beacon / check-in; carries system state&#xa0; /antino_downloads/{file}&#xa0; Antino upload&#xa0; Exfiltrated data from victims (files the operator downloads from victims)&#xa0; /antino_uploads/{file}&#xa0; Threat actor upload&#xa0; Toolkit delivery staging (files the operator uploads to victims)&#xa0; Antino uses the heartbeats folder to upload JSON-formatted heartbeat files containing host telemetry, including the session ID, timestamp, online/offline status, machine name, username, platform, and a campaign code defined in the backdoor configuration. Each implant session is assigned a randomly generated UUID, which is used as the heartbeat filename &#x201c;{session_id}.json&#x201d;. The implant uploads the heartbeat file to OneDrive during initial execution and resends every minute.&#xa0; Figure 17. Example heartbeat JSON.&#xa0;The directory naming is from the threat actor&#x2019;s perspective. &#x201c;antino_uploads/&#x201d; holds tools the operator pushes to victims, while &#x201c;antino_downloads/&#x201d; holds data the operator pulls from victims. The file-based polling model is characteristic of dead-drop C2 designs used to decouple operator activity from implant activity on the network.&#xa0; Mechanism 2: Outlook commands communication&#xa0; The Antino backdoor receives commands through email messages. The implant actively pulls commands from the threat actor&#x2019;s Outlook mailbox folder every 10 seconds. The protocol uses two message types: command emails contain tasking from the controller, while response emails contain the implant&#x2019;s results.&#xa0; Command messages are identified by the subject prefix command_req_[session_id] and responses by command_res_[session_id], as indicated in the HTTP GET request sent by Antino:&#xa0; Figure 18. Request from Antino to Outlook to get commands from emails.&#xa0;&#xa0;The body of each command message contains a JSON object with the information required for execution. It has three fields: command_type, the command to invoke; command_data, an object containing command-specific parameters; and request_id, a per-command identifier used to correlate the request with the corresponding response (the request_id is distinct from the implant session_id used in the message subject and heartbeat). For example, a cmd request has this body:&#xa0; Figure 19. The JSON sent in command request message.&#xa0;&#xa0;The response follows a similar structure. Its body contains a JSON object describing the outcome of command execution. The command_type field identifies the command that was executed, while request_id links the response to the corresponding request. The success field indicates whether the command succeeded, result contains the returned output, and error provides failure details or is null when execution succeeds. For example, a successful cmd response has the following body:&#xa0;&#xa0; Figure 20. The JSON sent in command response message.&#xa0;Antino-supported commands&#xa0;Antino is a comprehensive backdoor that supports several commands for host reconnaissance and execution. Across the reviewed Antino builds, Talos identified the following command handlers. Command availability varies by generation and build.&#xa0;&#xa0;&#xa0; Command/handler&#xa0; Capability&#xa0; cmd&#xa0; Runs cmd.exe /C and captures output&#xa0; powershell&#xa0; Runs powershell.exe -Command&#xa0; system_info&#xa0; Collects host and process context&#xa0; execute_program&#xa0; Executes an operator-supplied program&#xa0; list_files&#xa0; Enumerates a directory&#xa0; upload_file&#xa0; Transfers files from the threat actor&#x2019;s OneDrive to the compromised host&#xa0; download_file&#xa0; Exfiltrates files from the compromised host to the threat actor&#x2019;s OneDrive&#xa0; load_shellcode&#xa0; Runs operator-supplied shellcode in memory&#xa0; add_to_run&#xa0; Establishes Antino persistence by adding a Registry Run value&#xa0; exit&#xa0; Stops the Antino runtime&#xa0; Antino-supported commands. Command availability varies slightly by generation and build.&#xa0; The cmd and powershell commands allow the operator to execute commands directly through the Windows command shell or PowerShell and collect their output.&#xa0;&#xa0;&#xa0; Filesystem operations are handled through list_files, upload_file, and download_file. Similar to the C2 communication protocol, these names are written from the operator&#x2019;s perspective: upload_file transfers files from the threat actor&#x2019;s OneDrive to the compromised endpoint, while download_file reads a file from the endpoint and uploads it to OneDrive for operator retrieval.&#xa0;&#xa0; Antino provides two options for running actor-supplied code: load_shellcode and execute_program. The load_shellcode command sends a Base64-encoded payload in the command-request email body in the following JSON format:&#xa0; Figure 21. The load_shellcode command structure.Masking the loaded payload&#xa0; The use_sleep_mask parameter enables a defense evasion technique intended to reduce the secondary payload&#x2019;s exposure to memory scanners. When enabled, Antino hooks Sleep and VirtualAlloc and registers a vectored exception handler (VEH). The VirtualAlloc hook records the tracked memory region. When the tracked payload thread calls Sleep, the Sleep hook changes that region to non-executable (PAGE_READWRITE), encrypts its contents in place, and then calls the real Sleep function.&#xa0; &#xa0;After Sleep returns, an attempt to execute code from the encrypted, non-executable region triggers an access violation. The VEH confirms that the fault occurred within the tracked region, restores its previous memory protection, decrypts the content, and resumes execution. This technique is intended to reduce the time during which memory scanners can observe recognizable executable payload bytes. Although this technique does not mask the entire Antino process or guarantee evasion, it adds another layer of defense evasion by reducing the window in which memory scanners can identify the loaded payload.&#xa0; Abuse of the Windows Scripted Diagnostics framework workflow&#xa0;&#xa0; The Antino backdoor abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components. Both the execute_program and add_to_run commands use this technique.&#xa0; This workflow involves three components:&#xa0;&#xa0; Scripted Diagnostics Execution Engine (&#x201c;sdiageng.dll&#x201d;)&#xa0;Program Compatibility Wizard (PCW) troubleshooting package (&#x201c;C:\\Windows\\diagnostics\\system\\PCW&#x201d;)&#xa0;&#xa0;Scripted Diagnostics Native Host process (&#x201c;sdiagnhost.exe&#x201d;)&#xa0;Windows normally uses &#x201c;sdiageng.dll&#x201d; to load troubleshooting packages such as PCW, while &#x201c;sdiagnhost.exe&#x201d; executes their PowerShell scripts in a separate process.&#xa0; Antino initializes COM and creates an instance of CLSID {1F3D8AA5-9EBF-4EE4-85C2-EA40379AEDE8}, the CScriptedDiag class implemented by &#x201c;sdiageng.dll&#x201d;. It then initializes the engine with the legitimate PCW package and a blank diagnostic Answers XML document. The engine creates a temporary working copy of the package and returns its directory, such as &#x201c;C:\\Windows\\Temp\\SDIAG_<GUID>&#x201d;.&#xa0; Antino writes an attacker-controlled PowerShell script into this directory. For example, the add_to_run command generates a script that creates an HKCU Run key value:&#xa0; Figure 22. PowerShell script generated by Antino&#x2019;s add_to_run command.Antino then resumes the diagnostic workflow. The Scripted Diagnostics engine delegates execution to the native host, observed in runtime traces as %windir%\\SysWOW64\\sdiagnhost.exe -Embedding. The host subsequently executes result.ps1. The resulting Run key entry launches the selected Antino executable the next time the affected user signs in.&#xa0; &#xa0;The technique allows Antino to proxy PowerShell execution and the persistence-related registry modification through a Microsoft-signed diagnostic workflow. This can complicate behavioral attribution to the original implant, although it does not eliminate observable PowerShell, file-creation or registry telemetry.&#xa0; Figure 23. Antino calls CoCreateInstance to activate the Windows diagnostic COM class.&#xa0;Antino configuration&#xa0;&#xa0;Antino stores the configuration data in a custom PE section named .cfg. The on-disk structure begins with a four-byte little-endian JSON length followed by bytes XORed with the alternating key 0xAB 0xCD.&#xa0;&#xa0; In addition to its C2 configuration, Antino&#x2019;s embedded configuration contains two deployment settings, run and launch_mode. The run field controls whether Antino automatically installs a persistent copy when it starts. When set to true, Antino launches its installation task, stages the required files under %LOCALAPPDATA%\\Windows GatherOSStateKit\\, and creates an HKCU Run value. launch_mode is evaluated only when run is set to true. It defines which files constitute the persistent payload: exe or raw for standalone PE or dll for sideloading.&#xa0; Coverage&#xa0;The following ClamAV signatures detect and blocks this threat:&#xa0;&#xa0; Html.Trojan.UAT-11587-10060367-2&#xa0;Txt.Trojan.UAT-11587-10060385-5&#xa0;Txt.Trojan.UAT-11587-10060386-1&#xa0;Win.Trojan.UAT-11587-10060365-1&#xa0;Win.Trojan.UAT-11587-10060366-1&#xa0;Win.Trojan.UAT-11587-10060369-1&#xa0;Win.Trojan.UAT-11587-10060370-1&#xa0;Win.Trojan.UAT-11587-10060371-1&#xa0;Win.Trojan.UAT-11587-10060372-1&#xa0;Win.Trojan.UAT-11587-10060373-1&#xa0;Win.Trojan.UAT-11587-10060374-1&#xa0;Win.Trojan.UAT-11587-10060375-1&#xa0;Win.Trojan.UAT-11587-10060376-1&#xa0;Win.Trojan.UAT-11587-10060377-1&#xa0;Win.Trojan.UAT-11587-10060378-1&#xa0;Win.Trojan.UAT-11587-10060379-1&#xa0;Win.Trojan.UAT-11587-10060380-1&#xa0;Win.Trojan.UAT-11587-10060381-1&#xa0;Win.Trojan.UAT-11587-10060382-1&#xa0;Win.Trojan.UAT-11587-10060383-1&#xa0;Win.Trojan.UAT-11587-10060384-1&#xa0;The following Snort rules cover this threat:&#xa0;&#xa0; Snort 2: 1:66880, 1:66881, 1:66882&#xa0;Snort 3: 1:66880, 1:66881, 1:66882&#xa0;Indicators of compromise (IOCs)&#xa0;&#xa0;IOCs for this research can also be found at our GitHub repository here.&#xa0; e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 (malicious HTA stager - CSIS Indo-Pacific lure)&#xa0; e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf (malicious HTA stager - Bajo de Masinloc lure)&#xa0; 4d0fdce4c098635fe9b296c3a82c74645f9885eb5e383aa44a0fe7e50da3ca3f (malicious HTA stager - Taiwan information-warfare workshop lure)&#xa0; f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 (malicious HTA stager - Taiwan legislative-tax lure)&#xa0; 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a (malicious HTA stager - Venezuela and Ukraine news lure)&#xa0; 5a35fcd4458e808ab0fa52bb2a92923b60566ee4d7aaadaac7c95cad3d839562 (malicious HTA stager - Venezuela and Ukraine news lure)&#xa0; 17b53ffa8e005f0e82491d3f9c0a4984c44da52e1668a855c11a137f627c5b4b (malicious HTA stager - institutional disciplinary-action lure)&#xa0; 484ab497072ea09f12187b349f5b1c80754e4942408a009cccb20a2a3c8c6506 (malicious WSF stager - institutional disciplinary-action lure)&#xa0; 3a94910eb8022592ce030e6861359f7e980fc1b5a6ccd290cbb071d3e95ed02a (malicious HTA stager - TPiE inauguration lure)&#xa0; 6a1dbbfcfe6867ac83d35012b2717084388b4a34707efd0b725466dfd0e8fa56 (malicious WSF stager - TPiE inauguration lure)&#xa0; 75c12795016ae48b1bddd34a9f5adea63a12f58701eae01e1b4ab3d9dfa1513c (malicious HTA stager - Tehran bilateral-summit lure)&#xa0; bd8ddc8f33e0fe43147ee6f1713654996420a27c5d2cd91751ad67124ebc6fe4 (malicious WSF stager - Tehran bilateral-summit lure)&#xa0; b75492466462141c56d97b705f0c606faf272577631dc2822aa8d6bda53633b6 (malicious HTA stager - cross-border repression seminar lure)&#xa0; 23d5f1af8581ae200615d9a66d539f2043c3248b649e862557b379d7e8b7a3ac (malicious WSF stager - cross-border repression seminar lure)&#xa0; 0b4e5e017c0f0ccac79e13ca5d580a75af67a24ca0763f9ebfdaaeb1ba4fc739 (malicious HTA stager - Latin carnival lure)&#xa0; ae1b45fb56b9f1b9cb3ee30d2bb1279c9b90b70bb62f8de305d198c6a4e0585e (malicious WSF stager - Latin carnival lure)&#xa0; cd3509fa82e506cc6f2eeafa0a45d4b8b76a07edadd29779daf00568febcaba7 (malicious HTA stager - C-DAC lure)&#xa0; b8e6e83a73e6e07f8873c364dd2a4b830bceb60758163e2efcd7e387cb604655 (malicious WSF stager - C-DAC lure)&#xa0; 7969ae5f11fc163049c8eadba06f814f5edece13a707e6087c1c49011a45b838 (malicious HTA stager - Latin carnival lure variant)&#xa0; aea5e9029f9212d05bde10f7806d1f2819be45d167e6fd877b9fb1b11088ac90 (malicious WSF stager - Latin carnival lure variant)&#xa0; 7fa98efba59614cec0b7291aedee98764f8dc037b6cc798c93951a31208e9e32 (malicious HTA stager - internal-review lure)&#xa0; 65f4b9292e91abfa5adf42a03526932930c1c0a436bb186a7948fe6770295788 (malicious WSF stager - internal-review lure)&#xa0; 61a8f5add6c35f99c389012dbb2343061fd0b54611b40490b9a7f0b49d707da0 (Antino-chain Stage 2 JScript downloader and decryptor)&#xa0; 747b1d13bdf06956b5da5f47250fefd5284ebcf7961971732c3d348aa1a2d533 (Antino-chain Stage 2 JScript downloader and decryptor)&#xa0; a13182699a12a8dd9d07c336dbd8de5e9b086b9b09793b7de2e9761aa03ce1dc (Antino-chain Stage 2 JScript downloader and decryptor)&#xa0; 2f1513c822af0c6635dd3c69dc38f0b2f6e02012ea36415fff111a5d4d5fae05 (Antino-chain Stage 2 JScript downloader and decryptor)&#xa0; a0e91085f08956a9a7034ace73cee60cb211f5d96f02bc91a026601bde8f2221 (Antino-chain Stage 2 JScript downloader and decryptor - HTA branch)&#xa0; 47f98dfe01759a464e22d5ec55d012dccb38ce010dd73e3ba8d7ffefca12b4b2 (Antino-chain Stage 2 JScript downloader and decryptor - WSF branch)&#xa0; b3416726a064dd7f657bbb400adeb365eea7f8bb60783ad2d9da1a1d93768731 (Antino-chain Stage 2 JScript downloader and decryptor - HTA branch)&#xa0; 0a6fb71ab1362d065c7ec2678c1e73d9a0721b0e7099d392ba7559bb2eec4970 (Antino-chain Stage 2 JScript downloader and decryptor - WSF branch)&#xa0; f0c1dc6d6daa4d010932c7818ed5f22929c182f58e5f495fabe2fb3cfc835b97 (Antino-chain encrypted JScript orchestrator)&#xa0; 5555e904101689351a2a1359c9c06da0a57139a9470df7d26823c1b75db55041 (Antino-chain encrypted BinaryFormatter resource)&#xa0; 5168a2696a0ed858f996f388bfe94f952d475158f4ee6206816608936db005ca (Antino-chain encrypted BinaryFormatter resource)&#xa0; 7c2ac9c040b3300bffa7d2e435dbb1bc12e7efd644d2216d603c72121266395c (Antino-chain encrypted JScript orchestrator)&#xa0; d87201c1299a7f5854929645e6891c6c424d2a690031272bedacba7c5fe73a3e (Antino-chain encrypted BinaryFormatter resource)&#xa0; 334f39279ff3aae40fe74340c887ae018c75bc42790586bdf9070adb5889100c (Antino-chain encrypted BinaryFormatter resource)&#xa0; 077bd873217d8abfbb6482d11966ca34f3fef7ad5166f24fbc5dc3ddefe894a1 (Antino-chain encrypted JScript orchestrator)&#xa0; ad0bd2b45e2416fb1384bf30af068d857e7c06b4226615d66b55b610a34c5670 (Antino-chain encrypted BinaryFormatter resource)&#xa0; e2f59d8d5a81583ed482b6c7bf37699efdb2264e452cf7d8cfc0c54dfbd9ab3f (Antino-chain encrypted BinaryFormatter resource)&#xa0; 3a4c9020eeb5ef22a1ff443e606ccb6705fe287c583121c713d2c9f9f1f2a2af (Antino-chain encrypted JScript orchestrator)&#xa0; 4b614e5c37abaddca162119e42a969945caa681305e246e0ed0060ea9984008b (Antino-chain encrypted JScript orchestrator)&#xa0; c8e1239d7276178b6620f47ec4880494be1cb394477b223fc54bffb0947bff50 (Antino-chain encrypted BinaryFormatter resource)&#xa0; 079acd58a74479ac8b108b618d2a4da8a8bd560a04459cd90e2fec9da5027513 (Antino-chain encrypted BinaryFormatter resource)&#xa0; 8e1d68906d6de92f359945d3a95da1480e72773a3e8dea7682d6bf0f6699f75f (Antino-chain encrypted JScript orchestrator)&#xa0; 170b0eee60a335f32c1d0c19a0bb8d8bbc0a5b298ea9486b546f58d25cc8a464 (Antino-chain encrypted BinaryFormatter resource)&#xa0; b31ca75f73a9363b0e35042a41216c3f581eaa0b9cd78cb58f089c2e40babd40 (Antino-chain encrypted BinaryFormatter resource)&#xa0; d753a615aedf8e58ffc75b2b7ebd320c0cbe6bcb5cbb885db749a2a85c55d3bf (Antino-chain TestAssembly.dll downloader)&#xa0; 133a46ba41136ca21c93fb08c28446826d8c0d9b7923a16f2d152d595a710098 (Antino-chain TestAssembly.dll downloader)&#xa0; 9fc50cf28f86201fda8306926817b1ede41fdd993202515905dd072f6803542f (Antino-chain TestAssembly.dll downloader)&#xa0; d4cb2f5df16ec9b9c5b796ae55848534e15d4f8b8806f0431108fc7a99a2548a (Antino-chain TestAssembly.dll downloader)&#xa0; 131ac3e0df777910e0a32e43d5744bccb0490750d4c2adc359da41d76d383c46 (Antino-chain TestAssembly.dll downloader)&#xa0; 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff (Antino Gen 2 slc.dll backdoor)&#xa0; 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd (Antino Gen 2 standalone fake-installer backdoor)&#xa0; 1fadc90b61ce536abda78eb387a7f3d745f00c16775d3f762845ccc0fde567da (Antino Gen 1 slc.dll backdoor)&#xa0; 40e7e77aff603f4c2ef17b3bc8ea836e714d0734a1e5b946e52f95536ec5c91d (configured Antino Gen 1 standalone backdoor)&#xa0; 5c5c060b272cd4a5c3767edc0e9478bd35b7e1756e183d0446a5491bd65519cb (configured Antino standalone backdoor)&#xa0; 971cb2448b5d67dcc1f5eaa10d12e77f213035ad31230dc2ac7a510610a2059d (Antino Gen 2 standalone fake-installer backdoor)&#xa0; 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 (Antino Gen 2 standalone fake-installer backdoor)&#xa0; b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e (Antino Gen 2 standalone fake-installer backdoor)&#xa0; ca14ad0344dc7216f6da29a5cbe4237d886cc5257e8c3a48fb4885a311c9b800 (post-unpack Antino standalone backdoor memory image)&#xa0; e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 (Antino Gen 2 slc.dll backdoor)&#xa0; e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb (Antino Gen 2 slc.dll backdoor)&#xa0; fdbd047031c13a17c9f491c9355f44d587584ebe2b8927be8482e6c236c8e1c1 (Antino Gen 2 slc.dll backdoor)&#xa0; 103[.]27[.]110[.]220 (historical serving IP for the Antino payload hosted on wps-cn[.]com)&#xa0; osc-cdn[.]com (actor-used spear-phishing sender domain)&#xa0; oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev (Cloudflare Pages execution-tracking domain)&#xa0; d2nq35tel3ucuo[.]cloudfront[.]net (Antino-chain CloudFront staging domain)&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev (Antino-chain Cloudflare R2 staging domain)&#xa0; pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev (Antino-chain Cloudflare R2 staging domain)&#xa0; my-3lyt6wcp[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-qc39r814[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-662ylt3w[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-6g16qsfe[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-goq6xmbm[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-h3qli6kq[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-sv7c1fzs[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-u0up9qri[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-vtsdod2n[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-wgoxp32b[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; microsoft-flash[.]com (standalone Antino fake-installer delivery domain)&#xa0; wps-cn[.]com (standalone Antino fake-installer delivery domain)&#xa0; hxxps://microsoft-flash[.]com/download/flashcenter_pp_ax_install_en.exe (standalone Antino fake-installer delivery URL)&#xa0; hxxps://www[.]wps-cn[.]com/downloads/flashcenter_pp_ax_install_en.exe (standalone Antino fake-installer delivery URL)&#xa0; hxxps://my-662ylt3w[.]pages[.]dev/Institutional_Disciplinary_Action_Report_May_2026.hta (malicious HTA delivery URL)&#xa0; hxxps://my-662ylt3w[.]pages[.]dev/Institutional_Disciplinary_Action_Report_May_2026.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-6g16qsfe[.]pages[.]dev/the%20May%2027%20inauguration%20of%20the%20TPiE.hta (malicious HTA delivery URL)&#xa0; hxxps://my-6g16qsfe[.]pages[.]dev/the%20May%2027%20inauguration%20of%20the%20TPiE.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-goq6xmbm[.]pages[.]dev/Tehran_Bilateral_Summit_Proceedings_May2026.hta (malicious HTA delivery URL)&#xa0; hxxps://my-goq6xmbm[.]pages[.]dev/Tehran_Bilateral_Summit_Proceedings_May2026.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-h3qli6kq[.]pages[.]dev/CrossBorder_Repression_Seminar_Agenda.hta (malicious HTA delivery URL)&#xa0; hxxps://my-h3qli6kq[.]pages[.]dev/CrossBorder_Repression_Seminar_Agenda.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-sv7c1fzs[.]pages[.]dev/Extravaganza%20Latin%20Carnival.hta (malicious HTA delivery URL)&#xa0; hxxps://my-sv7c1fzs[.]pages[.]dev/Extravaganza%20Latin%20Carnival.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-u0up9qri[.]pages[.]dev/UO%20-C-DAC%20%281%29.hta (malicious HTA delivery URL)&#xa0; hxxps://my-u0up9qri[.]pages[.]dev/UO%20-C-DAC%20%281%29.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-vtsdod2n[.]pages[.]dev/Extravaganza%20Latin%20Carnival%20post%20copy.hta (malicious HTA delivery URL)&#xa0; hxxps://my-vtsdod2n[.]pages[.]dev/Extravaganza%20Latin%20Carnival%20post%20copy.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-wgoxp32b[.]pages[.]dev/Internal_Review_Dossier_0520.hta (malicious HTA delivery URL)&#xa0; hxxps://my-wgoxp32b[.]pages[.]dev/Internal_Review_Dossier_0520.wsf (malicious WSF delivery URL)&#xa0; hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/4oyE4n4ozLQ0.log (Antino-chain Stage 2 URL)&#xa0; hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/LtVGUSsyUTDA.log (Antino-chain Stage 2 URL)&#xa0; hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/TzzyYlYnJ40Z.log (Antino-chain Stage 2 URL)&#xa0; hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/tdyvHHVcrci8.log (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/Qw7Womin4X6N (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/kVFPxm1uAjOY (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/5SVIdjpRQjkZ (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/PbyfSk69AwVf (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/qMD71Z95clTf (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/HenUWB51MwpG (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/q9LgxIaU1CJK (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/BKvYRxPiGpbM (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/nswz3cb9lhuC (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/6HJV5qV5BTLs (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/MKJacn3hFt3Y (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/cX8MChhuVvzz (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/byrdvvZEZZlk (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/5TGrbjCCLa8M (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/s0p18dgHR4PZ (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/zlKDeyO3HuUS (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/icWMOGLJcfQO (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/5U7kzhvlYlVF (Antino-chain Stage 2 URL)&#xa0; hxxps://d2nq35tel3ucuo[.]cloudfront[.]net/9q9OlLKCm0an2ct1.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://d2nq35tel3ucuo[.]cloudfront[.]net/LwqPW64Xl0ti3q7s.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://d2nq35tel3ucuo[.]cloudfront[.]net/HsOw0YU9s11dxyr1.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/0u25lAqY58or53ra.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/gpv0IRMtvto6e8t2.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/HzjNPgRE9ir92e38.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/2laZiB2zvnx04jze.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/wyLwwCu43j1wf2pg.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/ThyI9pwewrh_a1pr.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/8ypvQLxJvggmrz94.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/vD68BdmB2ky28gcc.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/oaFE7PJHk0h_emqt.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/AcPP9fCvdjztmho8.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/7ChyKauxbnuftp68.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/KOOOT4a76st012bx.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/Ub4RJzNIrfleri8t.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0;&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/HeiqAW6ZGatherOsState.exe.luy (Antino sideload-package URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/HeiqAW6Zslc.dll.pzs (Antino backdoor delivery URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/HeiqAW6ZOsGather.dat.syk (Antino sideload-package URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgGatherOsState.exe.lzj (Antino sideload-package URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgslc.dll.iwq (Antino backdoor delivery URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgOsGather.dat.ael (Antino sideload-package URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/bzP3NcRPGatherOsState.exe.thl (Antino sideload-package URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/bzP3NcRPslc.dll.czh (Antino backdoor delivery URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/bzP3NcRPOsState.dat.mxb (Antino sideload-package URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/VD7F3WxnGatherOsState.exe.mtm (Antino sideload-package URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/VD7F3Wxnslc.dll.fsc (Antino backdoor delivery URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/VD7F3WxnOsState.dat.pgy (Antino sideload-package URL)&#xa0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-spotlight","cisco-talos-dns-security","cisco-talos-malware-protection","cisco-talos-email-threat-prevention","geo:inferred"],"relatedCves":[],"titleFingerprint":"11587-across-antino-asia-backdoor-china-government-nexus-organizations-policy-targets-uat","countryCodes":["CN","HK","IN","KH","MM","PH","PK","RU","SG","TH","TW","UA","VE"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/","type":"report","title":"Cisco Talos: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T10:00:01.000Z","addedAt":"2026-09-30T10:52:59.012Z","updatedAt":"2026-09-30T10:52:59.012Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"29b18006-26ab-4dde-a932-2572f4195ac6","slug":"talos-clearfake-webdav-infection-chain-delivers-amatera-stealer-3c066663","externalId":"6a97fbc85b9e1a0001b4e2c6","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager","description":"Cisco Talos began an investigation after observing a DLL named \"verification.google\" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.&#xA0;Pivoting around the similar WebDAV behavior led to a second loader named \"pf.ch\" and allowed us to reconstruct its earlier delivery stages. The chain uses a Cloudflare Worker to inject JavaScript code stored on BNB Smart Chain and a ClickFix prompt impersonating Google CAPTCHA, leading to download and execution of Amatera stealer. The chain is likely very similar to what has caused the WebDAV-based execution at the Ukraininan government organization.&#xA0;&#xA0;The two Amatera builds were tasked with different secondary payloads by their respective command-and-control (C2) infrastructure: the \"pf.ch\" loader was instructed to deploy a NativeAOT loader running ZigCryptoStealer and a Go-based reverse proxy, while the \"verification.google\" loader was instructed to install an unauthorized instance of NetSupport Manager.&#xA0;The NetSupport Manager installation contained configuration with the C2 server using an IP address based in Russia. With moderate confidence, we assess that \"verification.google\" branch attack was conducted by a Russian threat actor.&#xA0;&#xA0;&#xA0;In April 2026, Cisco Talos identified an unusual WebDAV DLL execution in endpoint telemetry from a Ukrainian government organization. The remote file was named \"verification.google\" and was launched through the 32-bit version of \"rundll32.exe\". This initial finding led us to two similar delivery chains, two different DLL loaders and two ACR/Amatera stealer payloads. Talos tracks the actor behind the observed \"verification.google\" activity as UAT-10820.&#xA0; Following the initial investigation, we decided to hunt for similar WebDAV and ordinal-execution patterns in an attempt to recover the full infection chain. Using VirusTotal, we were able to identify a full chain from a second DLL loader named \"pf.ch\".&#xA0;&#xA0; These two examples are a part of a wider set of recent campaigns delivering Amatera through different infection chains. In July 2026, Malwarebytes documented fake game and software downloads that used RenPy Loader, MSBuild and EtherHiding before delivering Amatera. Blackpoint Cyber described another fake-verification chain that used a signed Microsoft App-V script, configuration stored in Google Calendar and a payload concealed in a PNG image. Apart from the main payload malware family, we found no common infrastructure or other evidence linking those activities to the chains described in this post.&#xA0; Initial finding in endpoint telemetry&#xA0;The initial event that started the investigation was recorded in April 2026 and it showed an execution of a DLL file through a WebDAV UNC path together with startup of the Windows WebClient service. Apart from the initial command line, we had details of the checksum of the executed DLL but it was not clear what started the execution chain. It was time for hunting in open source intelligence repositories and Talos analytical platform. We wanted to find a similar execution with the similar loader and the payload family and ideally recover the whole infection chain which would likely point to how \"verification.google\" execution was triggered. This lead us to the \"pf.ch\" loader and the chain we discovered.&#xA0;&#xA0; Hunting reveals a second WebDAV delivery chain&#xA0;The \"pf.ch\" sample uses the same combination of WebDAV, a disguised DLL filename and ordinal execution through \"rundll32.exe\". We were also able to recover the full ClickFake related sequence leading to this loader. Figure 1 shows both chains, with dashed elements marking stages that were not directly recovered. With low to medium confidence, we assess that the two delivery chains are identical.&#xA0; Figure 1. Parallel WebDAV infection chains and Amatera secondary payloads.The discovered \"pf.ch\" loader chain was initiated by ClearFake Javascript injected into the content of a compromised site by a malicious Cloudflare worker.&#xA0;&#xA0; The C2 server returned configuration instructing the stealer to download a DLL side-loading package in which a signed Chrome component sideloads a malicious NativeAOT DLL, \"secur32.dll\". The DLL loads ZigCryptoStealer and uses a vulnerable driver to terminate EDR software. A separate x86 shellcode loader with a Go reverse TCP proxy is also downloaded as a secondary payload by the Amatera configuration sent by the C2 server.&#xA0;&#xA0; The secondary payload of the \"verification.google\" branch as instructed by its own C2, is a PowerShell script which attempts to install a sample of NetSupport Manager remote access tool.&#xA0; ClearFake retrieves browser code from BNB Smart Chain&#xA0;The \"pf.ch\" branch begins likely on a compromised website. A Cloudflare Worker injects a malicious JavaScript which queries BNB Smart Chain testnet contract 0x886d310Ac23e05EA705e24E513D19f53793832A9 through \"bsc-testnet-rpc[.]publicnode[.]com\". &#xA0; BNB Smart Chain is a public, Ethereum-compatible blockchain hosting transactions and smart contracts. The actor uses the contract as remotely changeable storage for encoded JavaScript, a technique known as EtherHiding. Based on the operating system of the victim&#x2019;s machine, the JavaScript code retrieves the next stage from the blockchain, which acts as a bulletproof hosting provider for the malicious code. Potent Pages previously documented unauthorized Cloudflare Workers querying the same first stage contract.&#xA0; The initial Javascript code contains routines to check for local and headless browser environments, identifies the operating system, and queries a second contract based on the result of the operation. If the victim is running Windows, it retrieves code from 0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383Ff and if the victim is running macOS, it uses 0x68DcE15C1002a2689E19D33A3aE509DD1fEb11A5. The response is Base64 decoded and evaluated as JavaScript.&#xA0; &#x200B;Figure 2. Modified, deobfuscated JavaScript selects an OS-specific BNB Smart Chain contract and evaluates the decoded response.The Windows browser stage creates a victim identifier, stores it in the cjs_id cookie and asks a tracking contract whether the goal for that identifier has already been reached. If the browser is not headless and the target is Windows, the script overlays a fake Google CAPTCHA-style checkbox onto the compromised page, instructing the victim to open the Windows Run dialog, paste the clipboard contents, and press Enter.&#xA0; Figure 3. Windows ClickFix verification prompt.&#x200B;&#xA0;The copied command opens a WebDAV path on a randomized subdomain of \"leaguejazire[.]com\", places the victim identifier in the path, and executes \"pf.ch\" through ordinal #1.&#xA0; &#x200B;Figure 4. Decoded Windows ClickFix command. Delayed expansion reconstructs pushd, rundll32 and popd at execution time.Censys documented the same Windows and macOS contracts in a blockchain-backed ClickFix chain, although the downstream payloads in that reporting differ from those analyzed here.&#xA0; The macOS browser stage uses the same headless-browser checks, victim tracking, and fake verification design, but its execution chain is different. It instructs the victim to open Terminal and paste a command that uses curl with a macOS user-agent string. The request goes to a subdomain of \"riyazinikokar[.]xyz\". Since the subject of our initial research was a customer running Windows, we have not further pursued the macOS side of the \"pf.ch\" branch.&#xA0;&#xA0; WebDAV launches disguised DLLs&#xA0;Both observed variants retrieve a 32-bit DLL over WebDAV using a file extension name that does not indicate it is a standard DLL file. Both use the 32-bit \"rundll32.exe\" process and invoke a function by calling the function ordinal #1. The corresponding first exports are moor in \"pf.ch\" and CfgInspectModuleData in \"verification.google\".&#xA0; Different initial loaders&#xA0;Although the WebDAV execution pattern is the same the two initial loaders use different code and protection methods.&#xA0; \"pf.ch\" uses exception-driven control flow&#xA0;The \"pf.ch\" loader is a packed 32-bit DLL whose only named export is moor with import table containing only AddVectoredExceptionHandler and __mb_cur_max functions.&#xA0;&#xA0; The packed code uses vectored exception handling, XOR loops, API hashing, and control-flow patterns, which makes the static analysis of the code more difficult. After the initialization, one of its threads is waiting for an event named hit. Once the event is triggered, it copies an embedded blob into memory and transfers control to it using Windows fibers. The next stage decoder uses XOR and LZNT1 to decode the final Amatera payload.&#xA0; The unpacked PE file, an Amatera sample, is also 32-bit, has no import table, and resolves APIs by walking loaded module export tables. The sample uses 32-to-64-bit transitions to execute system calls, possibly in an attempt to evade EDR hooks.&#xA0;&#xA0; The sample contains the build label 4.1.5-alpha and string GETWELLV2. Amatera is known to use the Steam community profiles as C2 dead drop resolvers, and the GETWELL2 string was observed in some previous samples as a name of a Steam community profile used to retrieve the IP address of the C2 server. Once C2 server address is resolved, the main configuration is downloaded.&#xA0;&#xA0; The Amatera payload was recovered only as a memory-resident artifact and was not observed to be written to disk. Its hash is nonetheless included in the indicator of compromise (IOC) list below, as memory derived hashes remain applicable to memory scanning.&#xA0; \"verification.google\" uses DLL hollowing in \"dbghelp.dll\"&#xA0;The \"verification.google\" variant does not immediately unpack its payload. It first prepares the state and then passes execution through a callback. The callback is registered using the dynamically resolved function TpAllocWork, an undocumented native NT internal function in \"ntdll.dll\". The callback is later executed asynchronously by Windows. The callback function implements most of the malicious unpacking functionality in a large control flow flattening loop.&#xA0; The loader resolves functions by hash, derives execution state from the environment and implements direct WoW64 syscall stubs. The stubs decode syscall numbers at runtime and call the WoW64 transition pointer instead of the corresponding exported \"ntdll.dll\" functions.&#xA0; &#x200B;Figure 5. Direct syscall stub used by \"verification.google\" before it maps and overwrites a clean \"dbghelp.dll\".The loader reconstructs its next stage from data in the .rdata section. It first maps a clean image of the legitimate \"dbghelp.dll\" in memory and then overwrites the beginning of its code section with the unpacked next stage. Finally, it restores executable protection before transferring control to the overwritten code section of the \"dbghelp.dll\".&#xA0;&#xA0; This module overwriting (stomping) technique is also known as DLL hollowing or module overloading. VMRay&#x2019;s technical overview of DLL hollowing describes the same core sequence: loading a legitimate DLL, overwriting its mapped code with malicious content, and executing from that overwritten region. G DATA documented module stomping in a HijackLoader chain that delivered ACRStealer, using different DLLs, \"evr.dll\", and \"rasapi32.dll\" rather than the \"dbghelp.dll\" observed in our case.&#xA0; Figure 6. The \"verification.google\" loader performs module stomping.Amatera C2 configurations&#xA0;\"pf.ch\" loaded Amatera resolves its C2 through a Telegraph page&#xA0;Before starting its Amatera C2 session, the Amatera sample used in \"pf.ch\" branch constructs the dead drop C2 URL \"https[:]//telegra[.]ph/Functions-04-03\". At the time of analysis, the page looked like a short Rust programming tutorial titled &#x201C;Functions.&#x201D; with an altered code example containing the string r.]MTQ1LjI0OS4xMDkuMTQ3)0(.&#xA0; Figure 7. \"Telegra.ph\" page used as a resolver.&#x200B;&#xA0;The raw HTML places the same value inside a println statement.&#xA0;&#xA0; &#x200B;&#xA0;Decoding MTQ1LjI0OS4xMDkuMTQ3 produces &#x201C;145.249.109[.]147&#x201D; as its C2 address.&#xA0;&#xA0; After resolving the address, the payload generates WoW64 transition gates, opens an Auxiliary Function Driver (AFD) socket and connects directly to \"145.249.109[.]147\" on TCP port 443.&#xA0;&#xA0; After connecting to the C2 server, Amatera connects to the GetEndpoints URL on the server. The response supplies randomized URI paths for different C2 functions. The stealer then uses the configuration path, together with an embedded build identifier, to retrieve its information collection rules.&#xA0;&#xA0; In the \"pf.ch\" build, a TLS-decoded HTTP buffer we were able to analyse contained a nonzero session identifier and an opaque 73-byte body whose framing is consistent with the ECDH and ChaCha20-Poly1305 protocol documented for recent Amatera versions.&#xA0;&#xA0; After removal of the transport and application encryption layers, the configuration is first Base64 decoded and then XOR decoded with the key 852149723\\x00, before parsing it as a JSON object.&#xA0;&#xA0; Apart from the rules for stealing data the received configuration also contained the instructions to load secondary payloads in a ld (load) json array.&#xA0;&#xA0; &#x200B;Figure 9. pf.ch Amatera tasking configuration showing secondary payload tasks.The ld field is an array of secondary loader tasks supplied by the Amatera controller. Within each entry, u is the download URL, tf selects the payload type and tr selects file-based (1) or fileless (2) execution. The loader supports executables, DLLs, command scripts, PowerShell, raw shellcode and MSI packages, which is described by the field tf. The p value determines task order, with lower positive values processed first.&#xA0; \"verification.google\" loaded Amatera configuration&#xA0;The \"verification.google\" Amatera build stores its bootstrap controller as an encrypted string. At runtime, it decrypts the fixed address \"45.150.34[.]2\" and connects to it directly on TCP port 443, while presenting \"github[.]com\" as the TLS server name and HTTP Host value. Unlike the \"pf.ch\" build, it does not use a public dead-drop resolver to obtain its initial C2 address. After connecting, it sends the GetEndpoints command to obtain working endpoints used for subsequent communication.&#xA0;&#xA0; As in the \"pf.ch\" Amatera payload the first accessed C2 URL is GetEndpoints. This branch&#x2019;s configuration contains over 400 entries across its browser, extension, messaging, wallet, and other-application collection lists, plus four file collection rules.&#xA0;&#xA0; The application rules in the configuration blob extend the initial browser related information collection to Telegram, Signal, WhatsApp, and other messaging data. They also cover over 100 desktop wallet locations and credential data from password managers, authenticators, FTP clients, mail clients, VPN software, and remote-access tools. Representative targets include KeePass, Bitwarden, 1Password, RoboForm, NordPass, WinAuth, Authy, FileZilla, AnyDesk, NordVPN and AzireVPN.&#xA0; Four file grabber rules cover the Desktop, Downloads, Documents and Windows Recent-items directory. Across those rules, more than 100 unique filename and extension patterns look for private keys, wallet backups, API and OAuth material, two-factor authentication data, password databases and certificate files such as .kdbx, .p12, .pfx and .pem. Most of the collection rules are focused on stealing cryptocurrency related data and credentials.&#xA0;&#xA0; Amatera secondary payloads&#xA0;Further on, we focus on the secondary loader tasks, which may point to a more advanced threat actor, based on the installed secondary payload type.&#xA0; The \"pf.ch\" Amatera build received two secondary tasks. One deployed a NativeAOT loader and ZigCryptoStealer, while the other ran a Go reverse TCP proxy from memory. The \"verification.google\" build received a PowerShell task that installed NetSupport Manager.&#xA0;&#xA0; Amatera branch Task type Follow-on capability pf.ch File-based archive Chrome DLL side-loading host, NativeAOT loader, process termination and ZigCryptoStealer pf.ch Fileless shellcode Go reverse TCP proxy over WebSocket and Yamux verification.google Fileless PowerShell Unauthorized NetSupport Manager remote access NativeAOT chain runs ZigCryptoStealer&#xA0;The \"jquery.min.js\" entry has priority 1, so Amatera processes it first. Its tf: 1 and tr: 1 values select the file-based executable handler. The server response does not have to be a PE file but it can also be an archive file. When this handler receives an archive, the loader extracts it to a temporary directory, enumerates the resulting *.exe file and launches the selected executable. The most recently observed response was a ZIP archive, SHA-256 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92.&#xA0;&#xA0; The archive included the file \"platform_experience_helper.exe\", a legitimate Google Chrome component. The executable imports GetUserNameExW from \"Secur32.dll\", which is a malicious DLL file in the archive which gets sideloaded by the Chrome component.&#xA0;&#xA0; The side-loaded \"Secur32.dll\" is a NET NativeAOT loader which decrypts and loads 2 PE files. The first file is a user mode payload and the second a vulnerable driver used to ter. The NativeAOT DLL starts &#x201C;C:\\Windows\\\"explorer.exe\" in a suspended state, manually maps the PE&#x2019;s headers and sections into the child, changes its initial thread context to the new entry point, and resumes it.&#xA0;&#xA0; The payload is a cryptocurrency stealer written in Zig language &#x2014; ZigCryptoStealer. It polls the clipboard, recognizes several cryptocurrency address formats and can replace matching values with addresses embedded in the payload.&#xA0;&#xA0; The payload makes a separate JSON-RPC eth_call through \"bsc[.]rpc[.]blxrbdn[.]com\" to BNB Smart Chain contract 0x7CC3cFC1Ac007B8c6566fD2C7419b15a75473468. This is a second use of EtherHiding in the infection chain, this time by the final payload rather than the browser delivery framework. VMRay has previously documented ZigCryptoStealer variants using BNB Smart Chain contracts as a dead drop for C2 configuration.&#xA0;&#xA0; ZigCryptoStealer disguises the request as a routine query for an ERC-20 token balance. It supplies a randomly generated cryptocurrency address, but the smart contract ignores it and instead returns text stored by the operator. The operator can change this text using the contract&apos;s setData(string) function. During our analysis, the contract returned \"lb[.]propertyfind[.]cc\", which ZigCryptoStealer then used as its C2 domain.&#xA0; The contract was deployed on March 16, 2026. The same wallet that deployed it made 39 successful setData calls through July 26. These calls provide a public history of the C2 values supplied to the malware with six domains active during July:&#xA0; Effective period in UTC Contract value June 30 &#x2013; July 5 fd[.]gstats-api-contact[.]cc July 5 &#x2013; 9 pkg[.]vogueatelier[.]cc July 9 &#x2013; 12 kffd3[.]vogueatelier[.]cc July 12 &#x2013; 18 kffd3[.]vexlatech[.]cc July 18 &#x2013; 26 static[.]quorashift[.]cc July 26 &#x2013; 30 lb[.]propertyfind[.]cc Talos used Cisco Umbrella to observe DNS activity for all six domains while they were active. The two most recent values also had the broadest query distribution. Umbrella data includes DNS quaries from 38 countries for \"static[.]quorashift[.]cc\" and 98 for \"lb[.]propertyfind[.]cc\". Queries for the current value came most often from the United States, Indonesia, Brazil, India, and Egypt.&#xA0;&#xA0; &#x200B;Figure 10. Cisco Umbrella distribution of DNS requests for \"lb[.]propertyfind[.]cc\" from the time it became the current contract value on July 26 through July 30. The map shows the reported share of DNS query origins.&#xA0;Passive DNS shows that all six domains resolved through shared Cloudflare addresses.&#xA0;&#xA0; The second decrypted PE is a signed Windows driver whose version information contains the names MOCOMSYS & DCRC and DCRCV_U Driver (for SCM). Its original filename is \"DCRCVDrv.sys\", and it exposes the device \\Device\\DCRCVDRV_U.&#xA0;&#xA0; The NativeAOT loader enumerates running processes, hashes their names, and compares the hashes with an internal target list of EDR software and other security tools. For every matched process name, it sends the process identifier to the driver with IOCTL 0x2205c0. The driver&#x2019;s handler accepts the four-byte PID, obtains a process handle and calls ZwTerminateProcess. We found no caller authorization check in that IOCTL branch. This gives the loader a kernel-mode process-termination primitive, a BYOVD driver.&#xA0; Figure 11. Modified decompilation from the malicious \"Secur32.dll\" user-mode loader. It enumerates processes, compares hashes of their names with its target list, and sends the PID of each match to the separate driver through IOCTL 0x2205c0.&#xA0;&#x200B; &#x200B;Figure 12. Modified decompilation from the separate signed \"DCRCVDrv.sys\" kernel driver. Its IOCTL handler reads the PID supplied by \"Secur32.dll\", obtains a process handle and calls ZwTerminateProcess. Types and names were replaced for readability. Go payload turns the host into a reverse TCP proxy&#xA0; The URL for the second secondary payload of the \"pf.ch\" branch yielded a binary shellcode blob with SHA-256 643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205.&#xA0; The 32-bit shellcode walks the process environment block (PEB) to find \"ntdll.dll\" and resolves LdrLoadDll, NtAllocateVirtualMemory, NtProtectVirtualMemory and NtFreeVirtualMemory . It then decrypts and decompresses the final payload stored in the shellcode using XOR to decrypt and LZNT1 to decompress the compressed proxy payload.&#xA0; The unpacked file has SHA-256 1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25.&#xA0; The payload is a Golang 32-bit Windows executable with main package &#x201C;github.com/acr/proxy-panel/cmd/bot&#x201D;. It includes HashiCorp Yamux network multiplexing library with C2 hardcoded &#x201C;wss://\"update[.]dubbedmuch[.]cc\"/&#x201D;.&#xA0; The proxy reads the Windows MachineGuid and hostname, then sends them over WebSocket Secure (wss) protocol. After the C2 server accepts the client, the program creates a Yamux server session, multiplexing outgoing communications over the same connection. Each logical stream supplies a source and destination address. The client connects to the requested destination and relays bytes in both directions.&#xA0; Figure 13. \"pf.ch\" Amatera runtime and tasking.&#x200B;&#xA0;PowerShell in the \"verification.google\" branch installs NetSupport Manager&#xA0; The secondary payload in this branch is \"https://kr[.]cedar2glanz[.]ru/jewel[.]js\". The tf value 4 of the single secondary payload loader instruction (ld) identifies the payload as PowerShell. The tr value 2 selects the execution path that retrieves the URL with PowerShell DownloadString and runs it through Invoke-Expression (IEX). Proofpoint&#x2019;s Amatera analysis documents the same ld, tf and tr semantics in more details.&#xA0;&#xA0; &#x200B;Figure 14. Reconstructed first PowerShell decoding layer.The next PowerShell stage dynamically resolves native functions and runs an environment check before installing the payload containing the following steps:&#xA0; It queries the C: volume serial and compares it with the hard-coded value 4E014A2F. The original expression returns true when this value matches, allowing execution to continue early and skipping the remaining checks.&#xA0;&#xA0;It calculates system uptime from Win32_OperatingSystem.LastBootUpTime. An uptime below 10 minutes returns false, causing the script to exit.&#xA0;It measures a native 500 ms NtDelayExecution call with GetTickCount64. If fewer than 400 ms appear to elapse, the gate returns false, which can identify an environment that accelerates or skips delays.&#xA0;It checks the processor count. Fewer than three processors unexpectedly returns true and allows execution to continue early rather than rejecting the low-resource system.&#xA0;It queries total physical memory. A reported value below 3.2GiB returns false.&#xA0;It queries Win32_VideoController and selects the largest reported AdapterRAM value. A reported maximum below 384 MiB returns false.&#xA0;It checks display-device friendly names and manufacturers against 36 strings associated with virtual graphics, remote displays, cloud platforms and generic virtual adapters. A match returns false.&#xA0;After the environment checks, the script derives an installation path by hashing MachineGuid|zdozwoqx3c. It also starts two background Powershell runspaces that request many legitimate URLs, including GitHub API, npm, Docker Hub, PyPI, NuGet, and PowerShell Gallery. The requests seem to generate decoy traffic to hide the malicious download within plausible developer activity.&#xA0; The script downloads \"https://phys[.]stunned-amniotic[.]com/hub[.]log\". Although the logs at the targeted system in Ukraine contained no evidence of accessing this URL we were able to download the file that was likely intended to be downloaded and executed by the Amatera stealer payload.&#xA0;&#xA0; The response at the time of analysis was a ZIP file with SHA256 bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b. Finally, the PowerShell validates ZIP entry paths, extracts the archive in the %APPDATA% directory, and starts \"hypersnap.exe\" executable without a visible window and creates a scheduled task triggered at user logon.&#xA0; The ZIP contains legitimate NetSupport Manager software&#xA0;The launched \"hypersnap.exe\" is a renamed, signed NetSupport Manager 12.44 \"client32.exe\". The \"client32.exe\" stub calls the export _NSMClient32@8 in signed \"PCICL32.DLL\", the main NetSupport client runtime containing the main functionality of the remote access platform.&#xA0;&#xA0; The actor-controlled \"client32.ini\" NetSupport Manager configuration enables silent operation, hides the system-tray interface, disables visible chat, message, disconnect, replay and help controls and configures \"paternal-angrily[.]com:443\" as the NetSupport HTTP Gateway.&#xA0; The client connects to the gateway, which acts as a proxy between the threat actor and the NetSupport Manager client installation at the victim system. The NetSupport client was configured to poll the gateway every 60 seconds. At the time of the analysis the domain resolved to the IP address \"212.118.56[.]166\", based in Russia.&#xA0;&#xA0; The NetSupport deployment used a license issued as KAKAN, with serial number NSM789508. The exact license file has appeared in numerous malicious NetSupport packages, including activity publicly tracked as EVALUSION and IClickFix. We therefore treat it as an indicator of shared deployment lineage rather than a unique threat actor identifier.&#xA0; NetSupport adds an operator driven capability after Amatera&#x2019;s automated collection. Amatera steals configured credentials, session data, cryptocurrency material, and selected files. An unauthorized NetSupport client can then provide screen and input control, file transfer, inventory, process and service management and remote command or PowerShell execution. This could let an operator inspect data outside Amatera&#x2019;s predefined rules, act on sessions from the original endpoint, or deploy additional tooling.&#xA0;&#xA0; Indicators of compromise (IOCs)&#xA0;The IOCs for this threat are also available at our GitHub repository here.&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","cisco-talos-antivirus","cisco-talos-malware-protection","cisco-talos-network-intrusion-prevention","threats","threat-spotlight","geo:inferred"],"relatedCves":[],"titleFingerprint":"amatera-chain-clearfake-delivers-infection-manager-netsupport-stealer-webdav-zigcryptostealer","countryCodes":["BR","EG","ID","IN","RU","UA","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/clearfake-webdav-infection-chain/","type":"report","title":"Cisco Talos: ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T10:01:07.000Z","addedAt":"2026-09-08T10:52:52.070Z","updatedAt":"2026-09-08T10:52:52.070Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]}],"pagination":{"page":1,"limit":20,"total":3,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:23:56.863Z","durationMs":35,"filters":{"search":null,"severity":[],"type":[],"country":["IN"],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}