đ Contexte
Cisco Talos a publiĂ© le 30 septembre 2026 une analyse technique dĂ©taillĂ©e d’un cluster d’activitĂ© malveillante dĂ©signĂ© UAT-11587, actif depuis septembre 2025 et attribuĂ© avec haute confiance Ă un acteur China-nexus. La campagne a ciblĂ© des organisations gouvernementales et de politique publique Ă travers l’Asie.
đŻ Victimologie
Au moins 16 environnements institutionnels affectés ou ciblés dans 8 pays (Taïwan, Inde, Philippines, Cambodge, Pakistan, Thaïlande, Myanmar, Syrie), représentant environ 350 endpoints compromis. Les secteurs visés incluent :
- Défense, militaire et sécurité nationale
- Gouvernement exécutif et administration publique
- Affaires étrangÚres et services diplomatiques
- Justice, forces de l’ordre et sĂ©curitĂ© intĂ©rieure
- Institutions législatives et parlementaires
- Think tanks, universités et institutions de recherche
- Société civile, droits humains et organisations de politique publique
đ§© Attribution
L’attribution China-nexus repose sur plusieurs indicateurs : mĂ©tadonnĂ©es de documents leurres contenant la balise de langue zh-CN, auteur en chinois simplifiĂ© (æȘćźäč), horodatage UTC+8, chemins de registre Cargo rĂ©fĂ©rençant rsproxy.cn (miroir Rust mainland China), et chevauchement d’infrastructure avec UNC6384 (rapportĂ© par Arctic Wolf). Symantec suit une activitĂ© similaire sous le nom Jewelbug.
âïž ChaĂźne d’infection (5 Ă©tapes)
- Stage 1 : Stager HTA ou WSF livré via Cloudflare Pages, exécuté par mshta.exe, avec tracking par beacon
- Stage 2 : Downloader JScript hébergé en HTA, télécharge 3 ressources chiffrées (RC4 + Base64 custom) depuis Cloudflare R2 ou Amazon CloudFront
- Stage 3 : Chaßne de désérialisation .NET BinaryFormatter (gadget ActivitySurrogateSelector + AxHost+State) pour charger TestAssembly.dll en mémoire
- Stage 4 : TestAssembly.dll (.NET downloader) télécharge le bundle DLL sideloading et le document leurre, lance GatherOsState.exe
- Stage 5 : DLL sideloading via GatherOsState.exe (binaire Microsoft ADK signé) chargeant slc.dll = backdoor Antino
đŠ Backdoor Antino
Antino est un backdoor compilĂ© en Rust (32 et 64 bits), nommĂ© d’aprĂšs AntinoApp dans son manifeste Windows. Il existe en deux gĂ©nĂ©rations (Gen1 : oct. 2025 ; Gen2 : dĂ©c. 2025 â janv. 2026). Ses capacitĂ©s incluent :
- Reconnaissance systĂšme (system_info)
- Exécution shell (cmd, powershell) via Windows Scripted Diagnostics (sdiagnhost.exe)
- Transfert de fichiers (upload_file, download_file)
- Chargement de shellcode en mémoire avec sleep masking (hooks Sleep/VirtualAlloc + VEH)
- Persistance via clé HKCU Run
- C2 exclusivement via Microsoft Graph API (Outlook pour les commandes, OneDrive pour heartbeat et fichiers)
Le canal C2 utilise des dead drops : commandes reçues via emails Outlook (sujets command_req_[session_id] / command_res_[session_id]), heartbeats JSON uploadés sur OneDrive (/antino/heartbeats/{id}.json). Le trafic C2 se fond dans les connexions légitimes vers graph.microsoft.com.
đ§ Techniques de livraison
- Spear-phishing avec spoofing d’expĂ©diteur (exploitation du dĂ©salignement SMTP envelope vs From header via Migadu, DMARC p=none)
- Clonage du widget piĂšce jointe Gmail (4 PNG Base64 inline + ancre vers URL Cloudflare Pages)
- Leurres thĂ©matiques : guerre de l’information Ă TaĂŻwan, fiscalitĂ© lĂ©gislative, prĂ©visions Indo-Pacifique CSIS, actualitĂ© gĂ©opolitique (Venezuela/Ukraine)
- ParamĂštre ?m= pour tracking par destinataire
đïž Infrastructure
L’acteur abuse massivement de services cloud lĂ©gitimes : Cloudflare Pages (livraison HTA/WSF, tracking), Cloudflare R2 (payloads chiffrĂ©s, leurres), Amazon CloudFront (scripts et leurres), Microsoft 365 (C2 post-compromission). Des domaines typosquattĂ©s (microsoft-flash[.]com, wps-cn[.]com) servent des installateurs Antino standalone.
đ Type d’article
Publication de recherche technique par Cisco Talos, visant Ă documenter une campagne d’espionnage China-nexus, fournir des IOCs exploitables et des signatures de dĂ©tection (ClamAV, Snort).
đ§ TTPs et IOCs dĂ©tectĂ©s
Acteurs de menace
TTP
- T1566.001 â Phishing: Spearphishing Attachment (Initial Access)
- T1566.002 â Phishing: Spearphishing Link (Initial Access)
- T1204.001 â User Execution: Malicious Link (Execution)
- T1059.001 â Command and Scripting Interpreter: PowerShell (Execution)
- T1059.003 â Command and Scripting Interpreter: Windows Command Shell (Execution)
- T1059.007 â Command and Scripting Interpreter: JavaScript (Execution)
- T1218.005 â System Binary Proxy Execution: Mshta (Defense Evasion)
- T1574.002 â Hijack Execution Flow: DLL Side-Loading (Defense Evasion)
- T1055 â Process Injection (Defense Evasion)
- T1027 â Obfuscated Files or Information (Defense Evasion)
- T1140 â Deobfuscate/Decode Files or Information (Defense Evasion)
- T1562.001 â Impair Defenses: Disable or Modify Tools (Defense Evasion)
- T1547.001 â Boot or Logon Autostart Execution: Registry Run Keys (Persistence)
- T1102.001 â Web Service: Dead Drop Resolver (Command and Control)
- T1071.003 â Application Layer Protocol: Mail Protocols (Command and Control)
- T1567.002 â Exfiltration Over Web Service: Exfiltration to Cloud Storage (Exfiltration)
- T1041 â Exfiltration Over C2 Channel (Exfiltration)
- T1082 â System Information Discovery (Discovery)
- T1083 â File and Directory Discovery (Discovery)
- T1057 â Process Discovery (Discovery)
- T1105 â Ingress Tool Transfer (Command and Control)
- T1620 â Reflective Code Loading (Defense Evasion)
- T1036.005 â Masquerading: Match Legitimate Name or Location (Defense Evasion)
- T1598.003 â Phishing for Information: Spearphishing Link (Reconnaissance)
- T1553.002 â Subvert Trust Controls: Code Signing (Defense Evasion)
IOC
- IPv4 :
103.27.110.220â AbuseIPDB · VT · ThreatFox - Domaines :
osc-cdn.comâ VT · URLhaus · ThreatFox - Domaines :
oisadjfoinsiduhfnoisdnfosdnoifnsoid.pages.devâ VT · URLhaus · ThreatFox - Domaines :
d2nq35tel3ucuo.cloudfront.netâ VT · URLhaus · ThreatFox - Domaines :
pub-abfa7742e315485a98a5fafd6dbfb68e.r2.devâ VT · URLhaus · ThreatFox - Domaines :
pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.devâ VT · URLhaus · ThreatFox - Domaines :
my-3lyt6wcp.pages.devâ VT · URLhaus · ThreatFox - Domaines :
my-qc39r814.pages.devâ VT · URLhaus · ThreatFox - Domaines :
my-662ylt3w.pages.devâ VT · URLhaus · ThreatFox - Domaines :
my-6g16qsfe.pages.devâ VT · URLhaus · ThreatFox - Domaines :
my-goq6xmbm.pages.devâ VT · URLhaus · ThreatFox - Domaines :
my-h3qli6kq.pages.devâ VT · URLhaus · ThreatFox - Domaines :
my-sv7c1fzs.pages.devâ VT · URLhaus · ThreatFox - Domaines :
my-u0up9qri.pages.devâ VT · URLhaus · ThreatFox - Domaines :
my-vtsdod2n.pages.devâ VT · URLhaus · ThreatFox - Domaines :
my-wgoxp32b.pages.devâ VT · URLhaus · ThreatFox - Domaines :
microsoft-flash.comâ VT · URLhaus · ThreatFox - Domaines :
wps-cn.comâ VT · URLhaus · ThreatFox - Domaines :
d32tpl7xt7175h.cloudfront.netâ VT · URLhaus · ThreatFox - URLs :
https://microsoft-flash.com/download/flashcenter_pp_ax_install_en.exeâ URLhaus - URLs :
https://www.wps-cn.com/downloads/flashcenter_pp_ax_install_en.exeâ URLhaus - URLs :
https://my-662ylt3w.pages.dev/Institutional_Disciplinary_Action_Report_May_2026.htaâ URLhaus - URLs :
https://my-662ylt3w.pages.dev/Institutional_Disciplinary_Action_Report_May_2026.wsfâ URLhaus - URLs :
https://my-6g16qsfe.pages.dev/the%20May%2027%20inauguration%20of%20the%20TPiE.htaâ URLhaus - URLs :
https://my-6g16qsfe.pages.dev/the%20May%2027%20inauguration%20of%20the%20TPiE.wsfâ URLhaus - URLs :
https://my-goq6xmbm.pages.dev/Tehran_Bilateral_Summit_Proceedings_May2026.htaâ URLhaus - URLs :
https://my-goq6xmbm.pages.dev/Tehran_Bilateral_Summit_Proceedings_May2026.wsfâ URLhaus - URLs :
https://my-h3qli6kq.pages.dev/CrossBorder_Repression_Seminar_Agenda.htaâ URLhaus - URLs :
https://my-h3qli6kq.pages.dev/CrossBorder_Repression_Seminar_Agenda.wsfâ URLhaus - URLs :
https://my-sv7c1fzs.pages.dev/Extravaganza%20Latin%20Carnival.htaâ URLhaus - URLs :
https://my-sv7c1fzs.pages.dev/Extravaganza%20Latin%20Carnival.wsfâ URLhaus - URLs :
https://my-u0up9qri.pages.dev/UO%20-C-DAC%20%281%29.htaâ URLhaus - URLs :
https://my-u0up9qri.pages.dev/UO%20-C-DAC%20%281%29.wsfâ URLhaus - URLs :
https://my-vtsdod2n.pages.dev/Extravaganza%20Latin%20Carnival%20post%20copy.htaâ URLhaus - URLs :
https://my-vtsdod2n.pages.dev/Extravaganza%20Latin%20Carnival%20post%20copy.wsfâ URLhaus - URLs :
https://my-wgoxp32b.pages.dev/Internal_Review_Dossier_0520.htaâ URLhaus - URLs :
https://my-wgoxp32b.pages.dev/Internal_Review_Dossier_0520.wsfâ URLhaus - URLs :
http://d2nq35tel3ucuo.cloudfront.net/4oyE4n4ozLQ0.logâ URLhaus - URLs :
http://d2nq35tel3ucuo.cloudfront.net/LtVGUSsyUTDA.logâ URLhaus - URLs :
http://d2nq35tel3ucuo.cloudfront.net/TzzyYlYnJ40Z.logâ URLhaus - URLs :
http://d2nq35tel3ucuo.cloudfront.net/tdyvHHVcrci8.logâ URLhaus - URLs :
http://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/Qw7Womin4X6Nâ URLhaus - URLs :
http://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/kVFPxm1uAjOYâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/5SVIdjpRQjkZâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/PbyfSk69AwVfâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/qMD71Z95clTfâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/HenUWB51MwpGâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/q9LgxIaU1CJKâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/BKvYRxPiGpbMâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/nswz3cb9lhuCâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/6HJV5qV5BTLsâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/MKJacn3hFt3Yâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/cX8MChhuVvzzâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/byrdvvZEZZlkâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/5TGrbjCCLa8Mâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/s0p18dgHR4PZâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/zlKDeyO3HuUSâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/icWMOGLJcfQOâ URLhaus - URLs :
http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/5U7kzhvlYlVFâ URLhaus - URLs :
https://d2nq35tel3ucuo.cloudfront.net/9q9OlLKCm0an2ct1.jsâ URLhaus - URLs :
https://d2nq35tel3ucuo.cloudfront.net/LwqPW64Xl0ti3q7s.txtâ URLhaus - URLs :
https://d2nq35tel3ucuo.cloudfront.net/HsOw0YU9s11dxyr1.txtâ URLhaus - URLs :
https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/0u25lAqY58or53ra.jsâ URLhaus - URLs :
https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/gpv0IRMtvto6e8t2.txtâ URLhaus - URLs :
https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HzjNPgRE9ir92e38.txtâ URLhaus - URLs :
https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/2laZiB2zvnx04jze.jsâ URLhaus - URLs :
https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/wyLwwCu43j1wf2pg.jsâ URLhaus - URLs :
https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/ThyI9pwewrh_a1pr.txtâ URLhaus - URLs :
https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/8ypvQLxJvggmrz94.txtâ URLhaus - URLs :
https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/vD68BdmB2ky28gcc.jsâ URLhaus - URLs :
https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/oaFE7PJHk0h_emqt.txtâ URLhaus - URLs :
https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/AcPP9fCvdjztmho8.txtâ URLhaus - URLs :
https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/7ChyKauxbnuftp68.jsâ URLhaus - URLs :
https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/KOOOT4a76st012bx.txtâ URLhaus - URLs :
https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/Ub4RJzNIrfleri8t.txtâ URLhaus - URLs :
https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6ZGatherOsState.exe.luyâ URLhaus - URLs :
https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6Zslc.dll.pzsâ URLhaus - URLs :
https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6ZOsGather.dat.sykâ URLhaus - URLs :
https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/hjgzBskgGatherOsState.exe.lzjâ URLhaus - URLs :
https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/hjgzBskgslc.dll.iwqâ URLhaus - URLs :
https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/hjgzBskgOsGather.dat.aelâ URLhaus - URLs :
https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/bzP3NcRPGatherOsState.exe.thlâ URLhaus - URLs :
https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/bzP3NcRPslc.dll.czhâ URLhaus - URLs :
https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/bzP3NcRPOsState.dat.mxbâ URLhaus - URLs :
https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/VD7F3WxnGatherOsState.exe.mtmâ URLhaus - URLs :
https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/VD7F3Wxnslc.dll.fscâ URLhaus - URLs :
https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/VD7F3WxnOsState.dat.pgyâ URLhaus - SHA256 :
e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34â VT · MalwareBazaar - SHA256 :
e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcfâ VT · MalwareBazaar - SHA256 :
4d0fdce4c098635fe9b296c3a82c74645f9885eb5e383aa44a0fe7e50da3ca3fâ VT · MalwareBazaar - SHA256 :
f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8â VT · MalwareBazaar - SHA256 :
01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31aâ VT · MalwareBazaar - SHA256 :
5a35fcd4458e808ab0fa52bb2a92923b60566ee4d7aaadaac7c95cad3d839562â VT · MalwareBazaar - SHA256 :
17b53ffa8e005f0e82491d3f9c0a4984c44da52e1668a855c11a137f627c5b4bâ VT · MalwareBazaar - SHA256 :
484ab497072ea09f12187b349f5b1c80754e4942408a009cccb20a2a3c8c6506â VT · MalwareBazaar - SHA256 :
3a94910eb8022592ce030e6861359f7e980fc1b5a6ccd290cbb071d3e95ed02aâ VT · MalwareBazaar - SHA256 :
6a1dbbfcfe6867ac83d35012b2717084388b4a34707efd0b725466dfd0e8fa56â VT · MalwareBazaar - SHA256 :
75c12795016ae48b1bddd34a9f5adea63a12f58701eae01e1b4ab3d9dfa1513câ VT · MalwareBazaar - SHA256 :
bd8ddc8f33e0fe43147ee6f1713654996420a27c5d2cd91751ad67124ebc6fe4â VT · MalwareBazaar - SHA256 :
b75492466462141c56d97b705f0c606faf272577631dc2822aa8d6bda53633b6â VT · MalwareBazaar - SHA256 :
23d5f1af8581ae200615d9a66d539f2043c3248b649e862557b379d7e8b7a3acâ VT · MalwareBazaar - SHA256 :
0b4e5e017c0f0ccac79e13ca5d580a75af67a24ca0763f9ebfdaaeb1ba4fc739â VT · MalwareBazaar - SHA256 :
ae1b45fb56b9f1b9cb3ee30d2bb1279c9b90b70bb62f8de305d198c6a4e0585eâ VT · MalwareBazaar - SHA256 :
cd3509fa82e506cc6f2eeafa0a45d4b8b76a07edadd29779daf00568febcaba7â VT · MalwareBazaar - SHA256 :
b8e6e83a73e6e07f8873c364dd2a4b830bceb60758163e2efcd7e387cb604655â VT · MalwareBazaar - SHA256 :
7969ae5f11fc163049c8eadba06f814f5edece13a707e6087c1c49011a45b838â VT · MalwareBazaar - SHA256 :
aea5e9029f9212d05bde10f7806d1f2819be45d167e6fd877b9fb1b11088ac90â VT · MalwareBazaar - SHA256 :
7fa98efba59614cec0b7291aedee98764f8dc037b6cc798c93951a31208e9e32â VT · MalwareBazaar - SHA256 :
65f4b9292e91abfa5adf42a03526932930c1c0a436bb186a7948fe6770295788â VT · MalwareBazaar - SHA256 :
61a8f5add6c35f99c389012dbb2343061fd0b54611b40490b9a7f0b49d707da0â VT · MalwareBazaar - SHA256 :
747b1d13bdf06956b5da5f47250fefd5284ebcf7961971732c3d348aa1a2d533â VT · MalwareBazaar - SHA256 :
a13182699a12a8dd9d07c336dbd8de5e9b086b9b09793b7de2e9761aa03ce1dcâ VT · MalwareBazaar - SHA256 :
2f1513c822af0c6635dd3c69dc38f0b2f6e02012ea36415fff111a5d4d5fae05â VT · MalwareBazaar - SHA256 :
a0e91085f08956a9a7034ace73cee60cb211f5d96f02bc91a026601bde8f2221â VT · MalwareBazaar - SHA256 :
47f98dfe01759a464e22d5ec55d012dccb38ce010dd73e3ba8d7ffefca12b4b2â VT · MalwareBazaar - SHA256 :
b3416726a064dd7f657bbb400adeb365eea7f8bb60783ad2d9da1a1d93768731â VT · MalwareBazaar - SHA256 :
0a6fb71ab1362d065c7ec2678c1e73d9a0721b0e7099d392ba7559bb2eec4970â VT · MalwareBazaar - SHA256 :
f0c1dc6d6daa4d010932c7818ed5f22929c182f58e5f495fabe2fb3cfc835b97â VT · MalwareBazaar - SHA256 :
5555e904101689351a2a1359c9c06da0a57139a9470df7d26823c1b75db55041â VT · MalwareBazaar - SHA256 :
5168a2696a0ed858f996f388bfe94f952d475158f4ee6206816608936db005caâ VT · MalwareBazaar - SHA256 :
7c2ac9c040b3300bffa7d2e435dbb1bc12e7efd644d2216d603c72121266395câ VT · MalwareBazaar - SHA256 :
d87201c1299a7f5854929645e6891c6c424d2a690031272bedacba7c5fe73a3eâ VT · MalwareBazaar - SHA256 :
334f39279ff3aae40fe74340c887ae018c75bc42790586bdf9070adb5889100câ VT · MalwareBazaar - SHA256 :
077bd873217d8abfbb6482d11966ca34f3fef7ad5166f24fbc5dc3ddefe894a1â VT · MalwareBazaar - SHA256 :
ad0bd2b45e2416fb1384bf30af068d857e7c06b4226615d66b55b610a34c5670â VT · MalwareBazaar - SHA256 :
e2f59d8d5a81583ed482b6c7bf37699efdb2264e452cf7d8cfc0c54dfbd9ab3fâ VT · MalwareBazaar - SHA256 :
3a4c9020eeb5ef22a1ff443e606ccb6705fe287c583121c713d2c9f9f1f2a2afâ VT · MalwareBazaar - SHA256 :
4b614e5c37abaddca162119e42a969945caa681305e246e0ed0060ea9984008bâ VT · MalwareBazaar - SHA256 :
c8e1239d7276178b6620f47ec4880494be1cb394477b223fc54bffb0947bff50â VT · MalwareBazaar - SHA256 :
079acd58a74479ac8b108b618d2a4da8a8bd560a04459cd90e2fec9da5027513â VT · MalwareBazaar - SHA256 :
8e1d68906d6de92f359945d3a95da1480e72773a3e8dea7682d6bf0f6699f75fâ VT · MalwareBazaar - SHA256 :
170b0eee60a335f32c1d0c19a0bb8d8bbc0a5b298ea9486b546f58d25cc8a464â VT · MalwareBazaar - SHA256 :
b31ca75f73a9363b0e35042a41216c3f581eaa0b9cd78cb58f089c2e40babd40â VT · MalwareBazaar - SHA256 :
d753a615aedf8e58ffc75b2b7ebd320c0cbe6bcb5cbb885db749a2a85c55d3bfâ VT · MalwareBazaar - SHA256 :
133a46ba41136ca21c93fb08c28446826d8c0d9b7923a16f2d152d595a710098â VT · MalwareBazaar - SHA256 :
9fc50cf28f86201fda8306926817b1ede41fdd993202515905dd072f6803542fâ VT · MalwareBazaar - SHA256 :
d4cb2f5df16ec9b9c5b796ae55848534e15d4f8b8806f0431108fc7a99a2548aâ VT · MalwareBazaar - SHA256 :
131ac3e0df777910e0a32e43d5744bccb0490750d4c2adc359da41d76d383c46â VT · MalwareBazaar - SHA256 :
09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cffâ VT · MalwareBazaar - SHA256 :
0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bdâ VT · MalwareBazaar - SHA256 :
1fadc90b61ce536abda78eb387a7f3d745f00c16775d3f762845ccc0fde567daâ VT · MalwareBazaar - SHA256 :
40e7e77aff603f4c2ef17b3bc8ea836e714d0734a1e5b946e52f95536ec5c91dâ VT · MalwareBazaar - SHA256 :
5c5c060b272cd4a5c3767edc0e9478bd35b7e1756e183d0446a5491bd65519â VT · MalwareBazaar
â ïž Ă propos de ces IOC â ils sont extraits automatiquement de l’article original le 5 octobre 2026 et n’ont pas fait l’objet d’une vĂ©rification externe. Un indicateur peut avoir Ă©tĂ© rĂ©attribuĂ© depuis : une IP de C2 peut redevenir un service lĂ©gitime, un domaine sinkholĂ© peut changer de propriĂ©taire. Aucune garantie d’exactitude ni d’actualitĂ© â contrĂŽlez leur validitĂ© avant tout usage opĂ©rationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.
đą Indice de vĂ©rification factuelle : 95/100 (haute)
- â blog.talosintelligence.com â source reconnue (liste interne) (20pts)
- â 52585 chars â texte complet (fulltext extrait) (15pts)
- â 143 IOCs dont des hashes (15pts)
- â 6/10 IOCs confirmĂ©s (AbuseIPDB, MalwareBazaar, ThreatFox, URLhaus, VirusTotal) (15pts)
- â 25 TTPs MITRE identifiĂ©es (15pts)
- â date extraite du HTML source (10pts)
- â acteur(s) identifiĂ©(s) : UAT-11587, Jewelbug (5pts)
- ⏠pas de CVE à vérifier (0pts)
IOCs confirmés externellement :
103.27.110.220(ip) â VT (6/91 dĂ©tections)e809da86bd814633âŠ(sha256) â VT (29/76 dĂ©tections)e6ff096a0562c004âŠ(sha256) â VT (30/76 dĂ©tections)osc-cdn.com(domain) â VT (10/91 dĂ©tections)oisadjfoinsiduhfnoisdnfosdnoifnsoid.pages.dev(domain) â VT (14/91 dĂ©tections)
đ Source originale : https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/