Skip to content

Executive Summary

The provided data consists of numerous encrypted resources and various domains/URLs associated with terms like "Antino-chain," "BinaryFormatter," "JScript orchestrator," and specific delivery endpoints referencing Cloudflare R2 staging domains, `.pages.dev`, and `cloudfront.net`. Several URLs are explicitly linked to malicious payloads, including HTA and WSF files, as well as executable/DLL files associated with Antino backdoor components. Furthermore, a series of domains like wps-cn.com and microsoft-flash.com are identified as standalone delivery points for fake installer artifacts. A large set of links points to "Antino-chain Stage 2 URLs," suggesting an established multi-stage delivery mechanism.

Facts Only

* Resources identified include: Antino-chain encrypted BinaryFormatter, JScript orchestrator, and specific backdoor files such as `slc.dll`, `fake-installer` artifacts, and various `.txt`, `.js`, and `.exe` files.
* Domains associated with the activity include `wps-cn.com` and `microsoft-flash.com` for fake installer delivery.
* Delivery infrastructure utilizes Cloudflare R2 staging domains (e.g., `pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev`) and CloudFront staging domains (e.g., `d2nq35tel3ucuo.cloudfront.net`).
* Specific malicious file delivery URLs include HTA/WSF files pointing to domains such as `my-662ylt3w.pages.dev`, `my-goq6xmbm.pages.dev`, and others.
* URLs point to staged data accessed via CloudFront for Antino-chain (e.g., `/4oyE4n4ozLQ0.log`).

Full Take

The pattern observed is the deployment of multi-stage, encrypted distribution systems utilizing legitimate-looking cloud infrastructure and web services to deliver malicious artifacts. The heavy reliance on obfuscation via encryption (BinaryFormatter, JScript) suggests an intent to evade static analysis, which is a classic method for malware distribution. The juxtaposition of high-level terminology ("Antino-chain") with low-level artifact details (specific DLLs, staging URLs) indicates an attempt to establish an authoritative narrative while hiding the operational mechanics. The deployment of multiple delivery domains across Cloudflare and personal Pages domains functions as a distributed façade, complicating attribution and making takedown efforts fragmented. This structure implies a systemic approach where the infrastructure itself is designed not just for delivery but for persistent, obfuscated operation. The implication is that resilience requires looking beyond the immediate file names to understand the flow of command and control embedded within these seemingly disparate artifacts. What specific logic governs the transition between the JScript orchestrators and the final payload files? How does one assess the trustworthiness of an infrastructure built on ephemeral, distributed hosting services versus centralized repositories?

From the original · Talos Intelligence Group

- Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts. - Talos first observed UAT-11587 activity in September 2025.
Read the full story at blog.talosintelligence.com
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor | Huntaegis