🔍 Contexte

Cisco Talos a publiĂ© le 30 septembre 2026 une analyse technique dĂ©taillĂ©e d’un cluster d’activitĂ© malveillante dĂ©signĂ© UAT-11587, actif depuis septembre 2025 et attribuĂ© avec haute confiance Ă  un acteur China-nexus. La campagne a ciblĂ© des organisations gouvernementales et de politique publique Ă  travers l’Asie.

🎯 Victimologie

Au moins 16 environnements institutionnels affectés ou ciblés dans 8 pays (Taïwan, Inde, Philippines, Cambodge, Pakistan, Thaïlande, Myanmar, Syrie), représentant environ 350 endpoints compromis. Les secteurs visés incluent :

  • DĂ©fense, militaire et sĂ©curitĂ© nationale
  • Gouvernement exĂ©cutif et administration publique
  • Affaires Ă©trangĂšres et services diplomatiques
  • Justice, forces de l’ordre et sĂ©curitĂ© intĂ©rieure
  • Institutions lĂ©gislatives et parlementaires
  • Think tanks, universitĂ©s et institutions de recherche
  • SociĂ©tĂ© civile, droits humains et organisations de politique publique

đŸ§© Attribution

L’attribution China-nexus repose sur plusieurs indicateurs : mĂ©tadonnĂ©es de documents leurres contenant la balise de langue zh-CN, auteur en chinois simplifiĂ© (æœȘ漚äč‰), horodatage UTC+8, chemins de registre Cargo rĂ©fĂ©rençant rsproxy.cn (miroir Rust mainland China), et chevauchement d’infrastructure avec UNC6384 (rapportĂ© par Arctic Wolf). Symantec suit une activitĂ© similaire sous le nom Jewelbug.

⛓ ChaĂźne d’infection (5 Ă©tapes)

  1. Stage 1 : Stager HTA ou WSF livré via Cloudflare Pages, exécuté par mshta.exe, avec tracking par beacon
  2. Stage 2 : Downloader JScript hébergé en HTA, télécharge 3 ressources chiffrées (RC4 + Base64 custom) depuis Cloudflare R2 ou Amazon CloudFront
  3. Stage 3 : Chaßne de désérialisation .NET BinaryFormatter (gadget ActivitySurrogateSelector + AxHost+State) pour charger TestAssembly.dll en mémoire
  4. Stage 4 : TestAssembly.dll (.NET downloader) télécharge le bundle DLL sideloading et le document leurre, lance GatherOsState.exe
  5. Stage 5 : DLL sideloading via GatherOsState.exe (binaire Microsoft ADK signé) chargeant slc.dll = backdoor Antino

🩠 Backdoor Antino

Antino est un backdoor compilĂ© en Rust (32 et 64 bits), nommĂ© d’aprĂšs AntinoApp dans son manifeste Windows. Il existe en deux gĂ©nĂ©rations (Gen1 : oct. 2025 ; Gen2 : dĂ©c. 2025 – janv. 2026). Ses capacitĂ©s incluent :

  • Reconnaissance systĂšme (system_info)
  • ExĂ©cution shell (cmd, powershell) via Windows Scripted Diagnostics (sdiagnhost.exe)
  • Transfert de fichiers (upload_file, download_file)
  • Chargement de shellcode en mĂ©moire avec sleep masking (hooks Sleep/VirtualAlloc + VEH)
  • Persistance via clĂ© HKCU Run
  • C2 exclusivement via Microsoft Graph API (Outlook pour les commandes, OneDrive pour heartbeat et fichiers)

Le canal C2 utilise des dead drops : commandes reçues via emails Outlook (sujets command_req_[session_id] / command_res_[session_id]), heartbeats JSON uploadés sur OneDrive (/antino/heartbeats/{id}.json). Le trafic C2 se fond dans les connexions légitimes vers graph.microsoft.com.

📧 Techniques de livraison

  • Spear-phishing avec spoofing d’expĂ©diteur (exploitation du dĂ©salignement SMTP envelope vs From header via Migadu, DMARC p=none)
  • Clonage du widget piĂšce jointe Gmail (4 PNG Base64 inline + ancre vers URL Cloudflare Pages)
  • Leurres thĂ©matiques : guerre de l’information Ă  TaĂŻwan, fiscalitĂ© lĂ©gislative, prĂ©visions Indo-Pacifique CSIS, actualitĂ© gĂ©opolitique (Venezuela/Ukraine)
  • ParamĂštre ?m= pour tracking par destinataire

đŸ—ïž Infrastructure

L’acteur abuse massivement de services cloud lĂ©gitimes : Cloudflare Pages (livraison HTA/WSF, tracking), Cloudflare R2 (payloads chiffrĂ©s, leurres), Amazon CloudFront (scripts et leurres), Microsoft 365 (C2 post-compromission). Des domaines typosquattĂ©s (microsoft-flash[.]com, wps-cn[.]com) servent des installateurs Antino standalone.

📄 Type d’article

Publication de recherche technique par Cisco Talos, visant Ă  documenter une campagne d’espionnage China-nexus, fournir des IOCs exploitables et des signatures de dĂ©tection (ClamAV, Snort).

🧠 TTPs et IOCs dĂ©tectĂ©s

Acteurs de menace

  • UAT-11587 (state-sponsored) —
  • Jewelbug (state-sponsored) — orkl.eu · Malpedia

TTP

  • T1566.001 — Phishing: Spearphishing Attachment (Initial Access)
  • T1566.002 — Phishing: Spearphishing Link (Initial Access)
  • T1204.001 — User Execution: Malicious Link (Execution)
  • T1059.001 — Command and Scripting Interpreter: PowerShell (Execution)
  • T1059.003 — Command and Scripting Interpreter: Windows Command Shell (Execution)
  • T1059.007 — Command and Scripting Interpreter: JavaScript (Execution)
  • T1218.005 — System Binary Proxy Execution: Mshta (Defense Evasion)
  • T1574.002 — Hijack Execution Flow: DLL Side-Loading (Defense Evasion)
  • T1055 — Process Injection (Defense Evasion)
  • T1027 — Obfuscated Files or Information (Defense Evasion)
  • T1140 — Deobfuscate/Decode Files or Information (Defense Evasion)
  • T1562.001 — Impair Defenses: Disable or Modify Tools (Defense Evasion)
  • T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys (Persistence)
  • T1102.001 — Web Service: Dead Drop Resolver (Command and Control)
  • T1071.003 — Application Layer Protocol: Mail Protocols (Command and Control)
  • T1567.002 — Exfiltration Over Web Service: Exfiltration to Cloud Storage (Exfiltration)
  • T1041 — Exfiltration Over C2 Channel (Exfiltration)
  • T1082 — System Information Discovery (Discovery)
  • T1083 — File and Directory Discovery (Discovery)
  • T1057 — Process Discovery (Discovery)
  • T1105 — Ingress Tool Transfer (Command and Control)
  • T1620 — Reflective Code Loading (Defense Evasion)
  • T1036.005 — Masquerading: Match Legitimate Name or Location (Defense Evasion)
  • T1598.003 — Phishing for Information: Spearphishing Link (Reconnaissance)
  • T1553.002 — Subvert Trust Controls: Code Signing (Defense Evasion)

IOC

  • IPv4 : 103.27.110.220 — AbuseIPDB · VT · ThreatFox
  • Domaines : osc-cdn.com — VT · URLhaus · ThreatFox
  • Domaines : oisadjfoinsiduhfnoisdnfosdnoifnsoid.pages.dev — VT · URLhaus · ThreatFox
  • Domaines : d2nq35tel3ucuo.cloudfront.net — VT · URLhaus · ThreatFox
  • Domaines : pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev — VT · URLhaus · ThreatFox
  • Domaines : pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev — VT · URLhaus · ThreatFox
  • Domaines : my-3lyt6wcp.pages.dev — VT · URLhaus · ThreatFox
  • Domaines : my-qc39r814.pages.dev — VT · URLhaus · ThreatFox
  • Domaines : my-662ylt3w.pages.dev — VT · URLhaus · ThreatFox
  • Domaines : my-6g16qsfe.pages.dev — VT · URLhaus · ThreatFox
  • Domaines : my-goq6xmbm.pages.dev — VT · URLhaus · ThreatFox
  • Domaines : my-h3qli6kq.pages.dev — VT · URLhaus · ThreatFox
  • Domaines : my-sv7c1fzs.pages.dev — VT · URLhaus · ThreatFox
  • Domaines : my-u0up9qri.pages.dev — VT · URLhaus · ThreatFox
  • Domaines : my-vtsdod2n.pages.dev — VT · URLhaus · ThreatFox
  • Domaines : my-wgoxp32b.pages.dev — VT · URLhaus · ThreatFox
  • Domaines : microsoft-flash.com — VT · URLhaus · ThreatFox
  • Domaines : wps-cn.com — VT · URLhaus · ThreatFox
  • Domaines : d32tpl7xt7175h.cloudfront.net — VT · URLhaus · ThreatFox
  • URLs : https://microsoft-flash.com/download/flashcenter_pp_ax_install_en.exe — URLhaus
  • URLs : https://www.wps-cn.com/downloads/flashcenter_pp_ax_install_en.exe — URLhaus
  • URLs : https://my-662ylt3w.pages.dev/Institutional_Disciplinary_Action_Report_May_2026.hta — URLhaus
  • URLs : https://my-662ylt3w.pages.dev/Institutional_Disciplinary_Action_Report_May_2026.wsf — URLhaus
  • URLs : https://my-6g16qsfe.pages.dev/the%20May%2027%20inauguration%20of%20the%20TPiE.hta — URLhaus
  • URLs : https://my-6g16qsfe.pages.dev/the%20May%2027%20inauguration%20of%20the%20TPiE.wsf — URLhaus
  • URLs : https://my-goq6xmbm.pages.dev/Tehran_Bilateral_Summit_Proceedings_May2026.hta — URLhaus
  • URLs : https://my-goq6xmbm.pages.dev/Tehran_Bilateral_Summit_Proceedings_May2026.wsf — URLhaus
  • URLs : https://my-h3qli6kq.pages.dev/CrossBorder_Repression_Seminar_Agenda.hta — URLhaus
  • URLs : https://my-h3qli6kq.pages.dev/CrossBorder_Repression_Seminar_Agenda.wsf — URLhaus
  • URLs : https://my-sv7c1fzs.pages.dev/Extravaganza%20Latin%20Carnival.hta — URLhaus
  • URLs : https://my-sv7c1fzs.pages.dev/Extravaganza%20Latin%20Carnival.wsf — URLhaus
  • URLs : https://my-u0up9qri.pages.dev/UO%20-C-DAC%20%281%29.hta — URLhaus
  • URLs : https://my-u0up9qri.pages.dev/UO%20-C-DAC%20%281%29.wsf — URLhaus
  • URLs : https://my-vtsdod2n.pages.dev/Extravaganza%20Latin%20Carnival%20post%20copy.hta — URLhaus
  • URLs : https://my-vtsdod2n.pages.dev/Extravaganza%20Latin%20Carnival%20post%20copy.wsf — URLhaus
  • URLs : https://my-wgoxp32b.pages.dev/Internal_Review_Dossier_0520.hta — URLhaus
  • URLs : https://my-wgoxp32b.pages.dev/Internal_Review_Dossier_0520.wsf — URLhaus
  • URLs : http://d2nq35tel3ucuo.cloudfront.net/4oyE4n4ozLQ0.log — URLhaus
  • URLs : http://d2nq35tel3ucuo.cloudfront.net/LtVGUSsyUTDA.log — URLhaus
  • URLs : http://d2nq35tel3ucuo.cloudfront.net/TzzyYlYnJ40Z.log — URLhaus
  • URLs : http://d2nq35tel3ucuo.cloudfront.net/tdyvHHVcrci8.log — URLhaus
  • URLs : http://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/Qw7Womin4X6N — URLhaus
  • URLs : http://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/kVFPxm1uAjOY — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/5SVIdjpRQjkZ — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/PbyfSk69AwVf — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/qMD71Z95clTf — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/HenUWB51MwpG — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/q9LgxIaU1CJK — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/BKvYRxPiGpbM — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/nswz3cb9lhuC — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/6HJV5qV5BTLs — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/MKJacn3hFt3Y — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/cX8MChhuVvzz — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/byrdvvZEZZlk — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/5TGrbjCCLa8M — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/s0p18dgHR4PZ — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/zlKDeyO3HuUS — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/icWMOGLJcfQO — URLhaus
  • URLs : http://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/5U7kzhvlYlVF — URLhaus
  • URLs : https://d2nq35tel3ucuo.cloudfront.net/9q9OlLKCm0an2ct1.js — URLhaus
  • URLs : https://d2nq35tel3ucuo.cloudfront.net/LwqPW64Xl0ti3q7s.txt — URLhaus
  • URLs : https://d2nq35tel3ucuo.cloudfront.net/HsOw0YU9s11dxyr1.txt — URLhaus
  • URLs : https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/0u25lAqY58or53ra.js — URLhaus
  • URLs : https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/gpv0IRMtvto6e8t2.txt — URLhaus
  • URLs : https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HzjNPgRE9ir92e38.txt — URLhaus
  • URLs : https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/2laZiB2zvnx04jze.js — URLhaus
  • URLs : https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/wyLwwCu43j1wf2pg.js — URLhaus
  • URLs : https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/ThyI9pwewrh_a1pr.txt — URLhaus
  • URLs : https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/8ypvQLxJvggmrz94.txt — URLhaus
  • URLs : https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/vD68BdmB2ky28gcc.js — URLhaus
  • URLs : https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/oaFE7PJHk0h_emqt.txt — URLhaus
  • URLs : https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/AcPP9fCvdjztmho8.txt — URLhaus
  • URLs : https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/7ChyKauxbnuftp68.js — URLhaus
  • URLs : https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/KOOOT4a76st012bx.txt — URLhaus
  • URLs : https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/Ub4RJzNIrfleri8t.txt — URLhaus
  • URLs : https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6ZGatherOsState.exe.luy — URLhaus
  • URLs : https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6Zslc.dll.pzs — URLhaus
  • URLs : https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6ZOsGather.dat.syk — URLhaus
  • URLs : https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/hjgzBskgGatherOsState.exe.lzj — URLhaus
  • URLs : https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/hjgzBskgslc.dll.iwq — URLhaus
  • URLs : https://pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/hjgzBskgOsGather.dat.ael — URLhaus
  • URLs : https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/bzP3NcRPGatherOsState.exe.thl — URLhaus
  • URLs : https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/bzP3NcRPslc.dll.czh — URLhaus
  • URLs : https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/bzP3NcRPOsState.dat.mxb — URLhaus
  • URLs : https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/VD7F3WxnGatherOsState.exe.mtm — URLhaus
  • URLs : https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/VD7F3Wxnslc.dll.fsc — URLhaus
  • URLs : https://pub-0173d1566dcd4fd49fa25f11f14bfe4c.r2.dev/VD7F3WxnOsState.dat.pgy — URLhaus
  • SHA256 : e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 — VT · MalwareBazaar
  • SHA256 : e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf — VT · MalwareBazaar
  • SHA256 : 4d0fdce4c098635fe9b296c3a82c74645f9885eb5e383aa44a0fe7e50da3ca3f — VT · MalwareBazaar
  • SHA256 : f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 — VT · MalwareBazaar
  • SHA256 : 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a — VT · MalwareBazaar
  • SHA256 : 5a35fcd4458e808ab0fa52bb2a92923b60566ee4d7aaadaac7c95cad3d839562 — VT · MalwareBazaar
  • SHA256 : 17b53ffa8e005f0e82491d3f9c0a4984c44da52e1668a855c11a137f627c5b4b — VT · MalwareBazaar
  • SHA256 : 484ab497072ea09f12187b349f5b1c80754e4942408a009cccb20a2a3c8c6506 — VT · MalwareBazaar
  • SHA256 : 3a94910eb8022592ce030e6861359f7e980fc1b5a6ccd290cbb071d3e95ed02a — VT · MalwareBazaar
  • SHA256 : 6a1dbbfcfe6867ac83d35012b2717084388b4a34707efd0b725466dfd0e8fa56 — VT · MalwareBazaar
  • SHA256 : 75c12795016ae48b1bddd34a9f5adea63a12f58701eae01e1b4ab3d9dfa1513c — VT · MalwareBazaar
  • SHA256 : bd8ddc8f33e0fe43147ee6f1713654996420a27c5d2cd91751ad67124ebc6fe4 — VT · MalwareBazaar
  • SHA256 : b75492466462141c56d97b705f0c606faf272577631dc2822aa8d6bda53633b6 — VT · MalwareBazaar
  • SHA256 : 23d5f1af8581ae200615d9a66d539f2043c3248b649e862557b379d7e8b7a3ac — VT · MalwareBazaar
  • SHA256 : 0b4e5e017c0f0ccac79e13ca5d580a75af67a24ca0763f9ebfdaaeb1ba4fc739 — VT · MalwareBazaar
  • SHA256 : ae1b45fb56b9f1b9cb3ee30d2bb1279c9b90b70bb62f8de305d198c6a4e0585e — VT · MalwareBazaar
  • SHA256 : cd3509fa82e506cc6f2eeafa0a45d4b8b76a07edadd29779daf00568febcaba7 — VT · MalwareBazaar
  • SHA256 : b8e6e83a73e6e07f8873c364dd2a4b830bceb60758163e2efcd7e387cb604655 — VT · MalwareBazaar
  • SHA256 : 7969ae5f11fc163049c8eadba06f814f5edece13a707e6087c1c49011a45b838 — VT · MalwareBazaar
  • SHA256 : aea5e9029f9212d05bde10f7806d1f2819be45d167e6fd877b9fb1b11088ac90 — VT · MalwareBazaar
  • SHA256 : 7fa98efba59614cec0b7291aedee98764f8dc037b6cc798c93951a31208e9e32 — VT · MalwareBazaar
  • SHA256 : 65f4b9292e91abfa5adf42a03526932930c1c0a436bb186a7948fe6770295788 — VT · MalwareBazaar
  • SHA256 : 61a8f5add6c35f99c389012dbb2343061fd0b54611b40490b9a7f0b49d707da0 — VT · MalwareBazaar
  • SHA256 : 747b1d13bdf06956b5da5f47250fefd5284ebcf7961971732c3d348aa1a2d533 — VT · MalwareBazaar
  • SHA256 : a13182699a12a8dd9d07c336dbd8de5e9b086b9b09793b7de2e9761aa03ce1dc — VT · MalwareBazaar
  • SHA256 : 2f1513c822af0c6635dd3c69dc38f0b2f6e02012ea36415fff111a5d4d5fae05 — VT · MalwareBazaar
  • SHA256 : a0e91085f08956a9a7034ace73cee60cb211f5d96f02bc91a026601bde8f2221 — VT · MalwareBazaar
  • SHA256 : 47f98dfe01759a464e22d5ec55d012dccb38ce010dd73e3ba8d7ffefca12b4b2 — VT · MalwareBazaar
  • SHA256 : b3416726a064dd7f657bbb400adeb365eea7f8bb60783ad2d9da1a1d93768731 — VT · MalwareBazaar
  • SHA256 : 0a6fb71ab1362d065c7ec2678c1e73d9a0721b0e7099d392ba7559bb2eec4970 — VT · MalwareBazaar
  • SHA256 : f0c1dc6d6daa4d010932c7818ed5f22929c182f58e5f495fabe2fb3cfc835b97 — VT · MalwareBazaar
  • SHA256 : 5555e904101689351a2a1359c9c06da0a57139a9470df7d26823c1b75db55041 — VT · MalwareBazaar
  • SHA256 : 5168a2696a0ed858f996f388bfe94f952d475158f4ee6206816608936db005ca — VT · MalwareBazaar
  • SHA256 : 7c2ac9c040b3300bffa7d2e435dbb1bc12e7efd644d2216d603c72121266395c — VT · MalwareBazaar
  • SHA256 : d87201c1299a7f5854929645e6891c6c424d2a690031272bedacba7c5fe73a3e — VT · MalwareBazaar
  • SHA256 : 334f39279ff3aae40fe74340c887ae018c75bc42790586bdf9070adb5889100c — VT · MalwareBazaar
  • SHA256 : 077bd873217d8abfbb6482d11966ca34f3fef7ad5166f24fbc5dc3ddefe894a1 — VT · MalwareBazaar
  • SHA256 : ad0bd2b45e2416fb1384bf30af068d857e7c06b4226615d66b55b610a34c5670 — VT · MalwareBazaar
  • SHA256 : e2f59d8d5a81583ed482b6c7bf37699efdb2264e452cf7d8cfc0c54dfbd9ab3f — VT · MalwareBazaar
  • SHA256 : 3a4c9020eeb5ef22a1ff443e606ccb6705fe287c583121c713d2c9f9f1f2a2af — VT · MalwareBazaar
  • SHA256 : 4b614e5c37abaddca162119e42a969945caa681305e246e0ed0060ea9984008b — VT · MalwareBazaar
  • SHA256 : c8e1239d7276178b6620f47ec4880494be1cb394477b223fc54bffb0947bff50 — VT · MalwareBazaar
  • SHA256 : 079acd58a74479ac8b108b618d2a4da8a8bd560a04459cd90e2fec9da5027513 — VT · MalwareBazaar
  • SHA256 : 8e1d68906d6de92f359945d3a95da1480e72773a3e8dea7682d6bf0f6699f75f — VT · MalwareBazaar
  • SHA256 : 170b0eee60a335f32c1d0c19a0bb8d8bbc0a5b298ea9486b546f58d25cc8a464 — VT · MalwareBazaar
  • SHA256 : b31ca75f73a9363b0e35042a41216c3f581eaa0b9cd78cb58f089c2e40babd40 — VT · MalwareBazaar
  • SHA256 : d753a615aedf8e58ffc75b2b7ebd320c0cbe6bcb5cbb885db749a2a85c55d3bf — VT · MalwareBazaar
  • SHA256 : 133a46ba41136ca21c93fb08c28446826d8c0d9b7923a16f2d152d595a710098 — VT · MalwareBazaar
  • SHA256 : 9fc50cf28f86201fda8306926817b1ede41fdd993202515905dd072f6803542f — VT · MalwareBazaar
  • SHA256 : d4cb2f5df16ec9b9c5b796ae55848534e15d4f8b8806f0431108fc7a99a2548a — VT · MalwareBazaar
  • SHA256 : 131ac3e0df777910e0a32e43d5744bccb0490750d4c2adc359da41d76d383c46 — VT · MalwareBazaar
  • SHA256 : 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff — VT · MalwareBazaar
  • SHA256 : 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd — VT · MalwareBazaar
  • SHA256 : 1fadc90b61ce536abda78eb387a7f3d745f00c16775d3f762845ccc0fde567da — VT · MalwareBazaar
  • SHA256 : 40e7e77aff603f4c2ef17b3bc8ea836e714d0734a1e5b946e52f95536ec5c91d — VT · MalwareBazaar
  • SHA256 : 5c5c060b272cd4a5c3767edc0e9478bd35b7e1756e183d0446a5491bd65519 — VT · MalwareBazaar

⚠ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 5 octobre 2026 et n’ont pas fait l’objet d’une vĂ©rification externe. Un indicateur peut avoir Ă©tĂ© rĂ©attribuĂ© depuis : une IP de C2 peut redevenir un service lĂ©gitime, un domaine sinkholĂ© peut changer de propriĂ©taire. Aucune garantie d’exactitude ni d’actualitĂ© — contrĂŽlez leur validitĂ© avant tout usage opĂ©rationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.


🟱 Indice de vĂ©rification factuelle : 95/100 (haute)

  • ✅ blog.talosintelligence.com — source reconnue (liste interne) (20pts)
  • ✅ 52585 chars — texte complet (fulltext extrait) (15pts)
  • ✅ 143 IOCs dont des hashes (15pts)
  • ✅ 6/10 IOCs confirmĂ©s (AbuseIPDB, MalwareBazaar, ThreatFox, URLhaus, VirusTotal) (15pts)
  • ✅ 25 TTPs MITRE identifiĂ©es (15pts)
  • ✅ date extraite du HTML source (10pts)
  • ✅ acteur(s) identifiĂ©(s) : UAT-11587, Jewelbug (5pts)
  • ⬜ pas de CVE Ă  vĂ©rifier (0pts)

IOCs confirmés externellement :

  • 103.27.110.220 (ip) → VT (6/91 dĂ©tections)
  • e809da86bd814633
 (sha256) → VT (29/76 dĂ©tections)
  • e6ff096a0562c004
 (sha256) → VT (30/76 dĂ©tections)
  • osc-cdn.com (domain) → VT (10/91 dĂ©tections)
  • oisadjfoinsiduhfnoisdnfosdnoifnsoid.pages.dev (domain) → VT (14/91 dĂ©tections)

🔗 Source originale : https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/