A China-linked espionage group (UAT-11587) targeted Asian government and policy organizations using highly tailored phishing emails and realistic decoy documents. After a click, malware ultimately installed the “Antino” backdoor, which then hid its command-and-control traffic inside normal Microsoft 365 activity by using Outlook and OneDrive via Microsoft Graph.
How the attack worked
The campaign, attributed to the group UAT-11587, began with a highly targeted phishing email sent to government and policy organizations in Asia. The lure documents were tailored to the recipient, including one that closely copied a real Taiwan Ministry of Finance ruling and another built around a fake workshop document on Taiwan's information warfare. Once a victim clicked through, the chain led to installation of the Antino backdoor.
A key technical trick was the fake Gmail attachment preview. Attackers recreated Gmail's normal attachment preview card almost pixel by pixel using images embedded directly in the email's HTML, then turned that fake preview into a clickable link pointing to an attacker-controlled page rather than an actual attachment.
Why it succeeded
Two factors let this slip past common defenses. First, the spoofed sender identity exploited a gap between email authentication checks: SPF passed because the real sending domain was technically authorized, but DMARC caught the mismatch between the visible From address and the actual sender. Because the impersonated domain's DMARC policy was set to monitoring rather than rejection, the failed message was still delivered to the inbox instead of being blocked.
Second, once installed, Antino did not rely on obvious external command-and-control infrastructure. Instead it pulled commands from an Outlook mailbox folder and used OneDrive for moving files, blending its activity into routine Microsoft 365 traffic that is harder to flag as anomalous.
What to watch for
- Attachment previews that behave like clickable links rather than static previews
- A visible From address that does not match the actual sending domain, especially combined with SPF pass/DMARC fail signals
- Unusually specific or sensitive government or policy content used as a lure, since tailored specificity is not proof of legitimacy
- Repeated, automated-looking emails with structured subject prefixes such as command_req or command_res, which can indicate command-and-control traffic disguised as mail
How to build resistance
Organizations in government, policy, and think tank environments should train staff to verify sender domains and hover over attachment previews before clicking. Security teams should review and strengthen DMARC enforcement so that failed alignment results in quarantine or rejection rather than simple monitoring. IT and security operations should also watch Microsoft 365 and Exchange logs for unusual mailbox folder polling or JSON-like structured data appearing in subject lines, as these can reveal covert backdoor activity hiding inside normal-looking email traffic.
Key findings
- UAT-11587 used convincing phishing emails with highly targeted decoy documents (including a copied Taiwan Ministry of Finance ruling) to get victims to open/click.
- Attackers used email spoofing that can pass SPF while still failing DMARC; weak DMARC enforcement (“monitoring rather than rejection”) allowed delivery to inboxes.
- Attackers recreated Gmail’s attachment preview card using embedded HTML images to make a fake attachment preview that linked to an attacker-controlled page.
- After execution, Antino used Microsoft 365 as cover for command-and-control: it pulled commands from an Outlook mailbox and used OneDrive folders for moving files and tools.
- Antino’s command workflow used specific email subject prefixes to distinguish tasking vs. results (e.g., command_req_[session_id] and command_res_[session_id]).
Who’s being targeted
- Commonly targeted roles: All employees (phishing awareness), Government/public sector staff, Policy/think tank staff, Executives and executive assistants, IT helpdesk and IT administrators, Security operations (M365 monitoring).
- Affected industries: Government (public sector), Policy organizations, Think tanks / civil society organizations.
- Attack channels: email, website.
- Impersonated: A trusted organization/source relevant to the recipient (e.g., public-sector/government context), The organization shown in the visible From address (spoofed), N/A (this is operator-to-malware messaging carried by email).
Red flags to watch for
- Email shows a realistic “attachment preview” but it is actually a clickable image/link
- Sender identity mismatch indicators (SPF passes but DMARC fails; weak DMARC enforcement lets it through)
- Unexpectedly sensitive or highly specific government/policy content used to create urgency/credibility
- Visible From domain does not match the actual sending domain
- Authentication inconsistencies (SPF pass with DMARC fail)
- Organization’s DMARC policy set to monitoring rather than reject/quarantine
- Repeated, automated-looking emails with structured subject prefixes
- Unusual mailbox folder activity and frequent polling intervals (every 10 seconds)
- JSON-like structured data embedded where it doesn’t belong (e.g., in email subject lines)
Frequently asked questions
What is the Antino backdoor?
Antino is the malware installed after a victim clicks a phishing lure in this campaign. It hides its command-and-control traffic inside normal Microsoft 365 activity by pulling commands from an Outlook mailbox and using OneDrive folders to move files and tools.
How did the fake Gmail attachment preview trick work?
Attackers recreated Gmail's normal attachment preview card almost pixel by pixel using images embedded in the email's HTML, then made the fake preview a clickable link to an attacker-controlled page.
Why did the spoofed emails reach inboxes despite failing DMARC?
The impersonated domain had a DMARC policy set to monitoring rather than rejection, so email that failed DMARC alignment still reached the inbox even though SPF passed.
Who was targeted in this campaign?
UAT-11587 targeted government, policy, and think tank organizations in Asia, using highly tailored decoy documents such as a copied Taiwan Ministry of Finance ruling.
Read the video transcript
You get a Gmail with a “Taiwan information warfare workshop” attachment that looks perfectly legit in the preview card. Here’s the trick: UAT-11587 rebuilt Gmail’s attachment preview almost pixel by pixel as an image. That “attachment” is actually a link to their site, not a file in your inbox. One click, and you land on their page, where malware like the Antino backdoor can get in, then hide inside normal Microsoft 365 traffic using Outlook and OneDrive as cover. Your move: any time you see a Gmail attachment preview, hover first. If it shows a web link instead of a google.com attachment, don’t click it.