Skip to content
Security & Trust

A spoofed email failed DMARC and still reached the inbox in an Asia spy campaign

Cisco Talos details a China-nexus group that used Microsoft 365 services to hide a backdoor

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
A spoofed email failed DMARC and still reached the inbox in an Asia spy campaign

AI-generated image for WebPulse. About our images

Key finding

Compromised endpoints: ~350 (Source: Cisco Talos (September 30, 2026))

A failed check that did not stop delivery

Email security often fails quietly. In a campaign Cisco Talos tracks as UAT-11587, the check worked and the forged message still arrived.

The lesson here is that a security check helps only if something acts on its result. A check can work as designed and still protect no one.

Talos says with high confidence that a China-nexus actor is behind UAT-11587. The researchers found the group while studying a March 2026 phishing wave. It hit policy experts, academics and think tanks in Taiwan. Later work showed government and security targets in other Asian countries too.

How the forged message got through

Every email carries two sender identities. One is a hidden envelope address used for routing. The other is the From line the reader sees.

The attackers set these to different domains. They sent through the mail service Migadu. The envelope used their own domain, osc-cdn[.]com. The From line showed the organization they were impersonating.

The first check, SPF, passed. It only confirms that Migadu may send for the envelope domain. It says nothing about the name the reader sees.

The second check, DMARC, compares the two identities. It flagged the mismatch and returned a failure. That is the right result.

In the message Talos reviewed, the impersonated domain used a policy of p=none. That setting asks receivers to monitor. It does not ask them to quarantine or reject. The receiving provider accepted the message.

The provider made the final delivery call. The policy gave it no request to block.

This is one reviewed message. The report does not say how common this setting is among the targets.

A fake attachment and tailored bait

The email rebuilt Gmail's attachment preview from four embedded images. The whole card was one link to a Cloudflare Pages address. That address carried a target identifier, so the operators could log each recipient.

The link began with //. Talos says security tools that pull out only full HTTP or HTTPS addresses may miss this form.

The bait fit its audience. One decoy copied a real Taiwan Ministry of Finance ruling on legislators' expenses. Another borrowed the framing of a CSIS Indo-Pacific forecast event. Talos says such content points to detailed prior knowledge of the targets.

~350
Compromised endpoints
Source: Cisco Talos (September 30, 2026)
10 confirmed, 5 probable
Institutional environments affected
Source: Cisco Talos (September 30, 2026)

Inside the infection chain

The link downloaded an HTA file. This is a Windows application format run by a built-in tool called mshta.exe. Talos describes a five-stage chain. Stages were fetched from cloud services, including Cloudflare R2 and Amazon CloudFront, and decrypted in memory.

Later stages abused BinaryFormatter. This .NET feature rebuilds objects from stored data. Attacker-supplied data made that step run malicious code inside the mshta.exe process.

The final payload was often Antino, a custom backdoor written in Rust. It reaches its operators through Microsoft 365. Messages sit in Outlook and OneDrive items, like a dead drop, where one side leaves notes and the other collects them.

The result is that the attacker does not need an obvious server of its own.

What Talos can and cannot say

Attribution rests on several clues together. A Taiwan-focused decoy file carried Simplified Chinese author text, a zh-CN language tag and a +08:00 time offset. Talos says this mix fits a mainland Chinese setup better than Taiwan or Hong Kong, where Traditional Chinese dominates.

Talos also warns that the time offset alone proves little. Ten Antino builds pointed to rsproxy.cn, a Rust package mirror meant for users in mainland China.

Activity ran from September 2025 to July 2026. Talos has moderate-to-high confidence that targets sat in eight countries, including Taiwan, India and the Philippines. It has moderate confidence that the goal is intelligence gathering.

Talos found overlaps with Symantec's Jewelbug research. It could not verify a link to that group's financially motivated activity. It tracks UAT-11587 separately. It rates a possible infrastructure overlap with UNC6384 as low confidence.

~57
Endpoints tied to India on June 8 and 9
Source: Cisco Talos (September 30, 2026)

Questions to put to your team

First, what DMARC policy does each domain we own publish? With p=none, receivers are only asked to monitor forged mail. Whether it arrives then depends on their own filters. Ask whether and when the policy can move to enforcement.

Second, can our mail systems flag messages where the envelope and visible sender differ?

Third, do our endpoints need mshta.exe? If not, can it be blocked?

Fourth, can our team tell normal Microsoft 365 traffic from a backdoor using the same services? Antino is built to look routine.

A control that only monitors will not stop a forgery. Decide which of your settings are meant to say no.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Cisco Talos.

Share this insight