🛡 MALWARE 🛡

Malware Antino utiliza Outlook y OneDrive para el C2 en campaña de espionaje Nexus en China.

🛡CyberObservatorio
Malware Antino utiliza Outlook y OneDrive para el C2 en campaña de espionaje Nexus en China.
Idioma

Malware Antino utiliza Outlook y OneDrive para el C2 en campaña de espionaje Nexus en China.

Fuente: The Hacker News

**Introducción Contextual**

En los últimos meses, las organizaciones gubernamentales y de políticas públicas en Asia han sido objeto de una nueva y sofisticada campaña de ciberataques orquestada por un grupo de amenazas con vínculos a China. Este fenómeno no solo pone de manifiesto la creciente vulnerabilidad de los sistemas de seguridad de diversas naciones, sino que también plantea serias preocupaciones sobre la integridad de la información y la privacidad de los ciudadanos. Los ataques han afectado a países como Taiwán, India, Filipinas, Camboya, Pakistán, Tailandia y Birmania, lo que indica un patrón de agresión cibernética que podría tener repercusiones más amplias en la geopolítica de la región.

La actividad del grupo, identificado como UAT-11587 por Cisco Talos, ha sido caracterizada por el uso de un nuevo backdoor, denominado Antino. Esta amenaza resalta la importancia de la ciberseguridad en el contexto de las relaciones internacionales, donde los actores estatales buscan obtener ventajas estratégicas a través de la recopilación de información sensible.

**Detalles Técnicos**

La campaña de ataque se detectó por primera vez en septiembre de 2025 y se relacionó con una serie de intentos de spear-phishing dirigidos a la comunidad académica, think tanks y organizaciones de la sociedad civil en Taiwán. Desde entonces, los ataques han escalado, afectando a un total de 16 entidades en ocho países asiáticos.

Antino es un backdoor compilado en Rust que permite realizar varias funciones de reconocimiento del host, ejecución de comandos y scripts de PowerShell, transferencia de archivos, carga de shellcode en memoria y persistencia en el sistema comprometido. Según la investigadora de seguridad Ashley Shen, el canal de comando y control nativo de Antino opera exclusivamente a través de Microsoft 365, utilizando Microsoft Graph para interactuar con Outlook y OneDrive.

El grupo UAT-11587 muestra algunas similitudes en tácticas con otro grupo conocido como Jewelbug, que ha sido caracterizado como un colectivo de hackers a sueldo con sede en China, involucrado en operaciones de espionaje y fraudes relacionados con criptomonedas. Sin embargo, la investigación de Cisco Talos no ha logrado establecer una conexión directa entre la campaña de espionaje y las actividades financieramente motivadas de Jewelbug, lo que lleva a clasificar a UAT-11587 como un conjunto de actividades separado.

Un par de indicadores adicionales apuntan al origen chino de la amenaza. En primer lugar, varios de los outputs de construcción de Antino incluyen rutas de registro de Cargo que hacen referencia a rsproxy[.]cn, un servicio de proxy y espejo de alta velocidad para crates.io destinado a China continental. En segundo lugar, un downloader de JavaScript asociado con UAT-11587 hace referencia a "d32tpl7xt7175h.cloudfront[.]net", un dominio de CloudFront previamente señalado por Arctic Wolf en conexión con una campaña de un actor de amenazas vinculado a China, conocido como UNC6384, que atacó entidades diplomáticas y gubernamentales europeas el año pasado utilizando una vulnerabilidad no parcheada en accesos directos de Windows.

**Impacto y Consecuencias**

La actividad de UAT-11587 no se ha limitado a Asia, ya que se ha observado que el grupo también ha dirigido su atención a organizaciones en Siria alrededor de mayo de 2026. Esto indica que su alcance es más amplio y podría tener implicaciones para la seguridad cibernética global. Los ataques del grupo han mostrado un incremento significativo entre marzo y principios de junio de 2026, con una "ola concentrada" de ataques reportada el 8 y 9 de junio de 2026, donde se vieron comprometidos decenas de sistemas asociados con la infraestructura de TI gubernamental.

La elección del spear-phishing como vector de acceso inicial no es sorprendente, aunque el contenido de las señuelos utilizados sugiere que el actor llevó a cabo una extensa investigación de las organizaciones objetivo para adaptar el contenido y maximizar las posibilidades de éxito.

**Contexto Histórico**

Este tipo de ciberataques no son un fenómeno nuevo, y la historia reciente ha estado marcada por incidentes similares que involucran a actores estatales que utilizan tácticas de phishing para infiltrarse en redes de gobiernos y organizaciones. Por ejemplo, hemos sido testigos de campañas de ciberespionaje que han afectado a sectores críticos y de defensa en varios países, lo que subraya la necesidad de una mayor preparación y resiliencia frente a estas amenazas.

**Recomendaciones**

Para mitigar el riesgo asociado con campañas como la de UAT-11587, es fundamental que las organizaciones implementen medidas de seguridad robustas. Esto incluye la capacitación continua del personal en la identificación de correos electrónicos de phishing, la implementación de soluciones de seguridad que analicen el contenido de los correos electrónicos y la adopción de políticas de seguridad que fomenten buenas prácticas en el uso de herramientas de colaboración como Microsoft 365. Además, es esencial mantener los sistemas actualizados para protegerse contra vulnerabilidades conocidas y emplear mecanismos de autenticación multifactor para salvaguardar el acceso a información sensible.

En resumen, la amenaza que representa UAT-11587 no solo pone en riesgo a las entidades gubernamentales en Asia, sino que también plantea un desafío significativo para la ciberseguridad a nivel global. La vigilancia constante y la adaptación a nuevas tácticas de los atacantes son cruciales para la defensa en este entorno digital cada vez más hostil.

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Source: The Hacker News

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster under the monikerUAT-11587. The threat actor was first detected in September 2025 in connection with a spear-phishing campaign directed against Taiwan's academic, think tank, and civil society policy community. Since then, attacks linked to the intrusion set have expanded to target 16 entities across eight Asian countries. "Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence," security researcher Ashley Shensaid. "Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive." UAT-11587 is assessed to share some level of overlap with Jewelbug, which, in turn, exhibits tactical similarities with China-aligned clusters known as CL-STA-0049, Earth Alux, Ink Dragon, and REF7707. A report published by Broadcom-owned Symantec and Carbon Black in August 2026characterizedJewelbug as a China-based hackers-for-hire group that carries out espionage operations and a for-profit cryptocurrency fraud business. However, Cisco Talos said its own investigation has failed to unearth a connection between the espionage campaign and Jewelbug's financially motivated activity, prompting it to designate UAT-11587 as a separate activity set. The challenges in establishing definitive links notwithstanding, the adversary has been classified as China-nexus with high confidence, citing the presence of zh-CN language and Simplified Chinese metadata in the lure documents and the UTC+08:00 time zone in the spear-phishing message header. "The campaign's lure theme and targeting provide additional contextual support," Talos said. "Its lures and observed targets include Taiwanese political, legislative, civil defense, and policy research subjects, together with regional government, maritime, diplomatic, and security themes. This collection focus is consistent with China-nexus actor interests." Two other indicators that point to a China-nexus are below - Nearly a dozen distinct Antino build outputs feature Cargo registry paths referencing rsproxy[.]cn, a high-speed domestic mirror and proxy service for crates.io catering to mainland China A JavaScript downloader associated with UAT-11587 that references "d32tpl7xt7175h.cloudfront[.]net," a CloudFront domain previously flagged by Arctic Wolf in connection with a campaign conducted by a China-affiliated threat actor known asUNC6384targeting European diplomatic and government entities last year using an unpatched Windows shortcut vulnerability. Evidence indicates that UAT-11587 has also trained its sights on organizations in Syria around May 2026, indicating a focus beyond Asia. Attacks mounted by the threat actor have been found to spike between March and early June 2026, with a "concentrated wave" taking place on June 8 and 9, 2026, targeting dozens of systems associated with government IT infrastructure. While the choice of spear-phishing as an initial access vector is unsurprising, the choice of the lures employed suggests the threat actor conducted extensive reconnaissance of the target organizations in order to tailor the content and maximize the chance of success. In an attempt to lend credibility to the emails, UAT-11587 is said to have spoofed sender identities trusted by the intended recipients to bypassSPF and DMARC security checksand ensure that the messages land on the victims' inboxes. "Another social engineering technique used for initial access in this campaign was the closely replicated reconstruction of Gmail's native attachment preview widget inside the email HTML body," Shen explained. "The actor replicated the styling of Gmail's attachment card using four inline PNG images embedded as Base64-encoded MIME parts." "The entire attachment card was wrapped in an anchor tag pointing to an attacker-controlled [Cloudflare Pages] URL. When a Gmail user opens the email in a browser, Gmail's renderer faithfully displays the attacker-controlled HTML, producing a fake attachment widget that is visually indistinguishable from a legitimate Gmail attachment preview." An analysis of the lures demonstrates a propensity to target audiences interested in foreign affairs, international security, and government policy, Talos added. The attack chain itself is a five-stage process that begins with a HTA or WSF stager and culminates in the deployment of Antino. The Cloudflare URL in the phishing email leads to the download of an HTA or WSF file that's then executed to retrieve a JavaScript downloader and decryptor. The next stage triggers a .NET deserialization chain to load "TestAssembly.dll," a .NET downloader and launcher that's responsible for three actions - Download and open the lure document to the victim. Download a decoy Calculator executable. Download and launch the Antino backdoor. The implant ("slc.dll") is launched by means of DLL sideloading using a legitimate Microsoft-signed binary ("GatherOsState.exe"). Once launched, the Rust-compiled malware communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, instead of depending on a conspicuous dedicated command-and-control (C2) server. Antino is no different from other backdoors of its kind in that it supports host reconnaissance, command execution, and persistence. It can also list running processes, enumerate directories, run PowerShell scripts, shellcode, operator-supplied programs, and commands using "cmd.exe" For C2, it uses Outlook for command exchange and OneDrive for heartbeat and file transfer. Specifically, it fetches commands from the threat actor's Outlook mailbox folder every 10 seconds by looking for messages with the subject prefix "command_req_[session_id]." "The Antino backdoor abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components," Talos said. "This can complicate behavioral attribution to the original implant, although it does not eliminate observable PowerShell, file-creation, or Registry telemetry."

Malware Antino utiliza Outlook y OneDrive para el C2 en campaña de espionaje Nexus en China. | Ciberseguridad - NarcoObservatorio