Executive Summary
Facts Only
* Resources identified include: Antino-chain encrypted BinaryFormatter, JScript orchestrator, and specific backdoor files such as `slc.dll`, `fake-installer` artifacts, and various `.txt`, `.js`, and `.exe` files.
* Domains associated with the activity include `wps-cn.com` and `microsoft-flash.com` for fake installer delivery.
* Delivery infrastructure utilizes Cloudflare R2 staging domains (e.g., `pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev`) and CloudFront staging domains (e.g., `d2nq35tel3ucuo.cloudfront.net`).
* Specific malicious file delivery URLs include HTA/WSF files pointing to domains such as `my-662ylt3w.pages.dev`, `my-goq6xmbm.pages.dev`, and others.
* URLs point to staged data accessed via CloudFront for Antino-chain (e.g., `/4oyE4n4ozLQ0.log`).
Full Take
From the original · Talos Intelligence Group
- Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts. - Talos first observed UAT-11587 activity in September 2025.Read the full story at blog.talosintelligence.com
