INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Antino Backdoor Exploits Outlook and OneDrive for China-Nexus Espionage
| 2026-09-30 11:57 MEDIUM HIGH MALWARE & BOTNETS STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A China-linked group, identified as UAT-11587, has been using the Antino backdoor and Microsoft 365 to spy on Asian governments since at least September 2025. The attackers created highly targeted documents that suggested they had researched their victims, including a fake workshop document about Taiwan's information warfare and a document that closely copied a real Taiwan Ministry of Finance ruling. They used phishing emails with convincing content, spoofing legitimate domains and exploiting gaps in email security measures to deliver the malware. Once inside Microsoft 365, Antino hid by using Microsoft Graph to read commands from an Outlook mailbox and send stolen files to OneDrive, allowing its traffic to blend in with normal activity. By July 2026, UAT-11587 had hit at least 16 government and policy organizations across eight Asian countries.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
ca14ad••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
7c2ac9••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
ae1b45••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
b31ca7••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
my•••••.dev
d2•••••.net
my•••••.dev
my•••••.dev
Te•••••.dll
hj•••••.dll
oa•••••.txt
gp•••••.txt
28f754••••••••••••••••••••••••••
5510d3••••••••••••••••••••••••••
66b403••••••••••••••••••••••••••
cc648b••••••••••••••••••••••••••
103.27.•••.•••
e3b2bb••••••••••••••••••••••••••••••••••
13425b••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CarbonCarbon
Target & Sectors
ASEAN
ASEAN
SOUTH_ASIA
SOUTH_ASIA
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
Incident Timeline
June 8 and 9, 2026
Threat actors used the Antino backdoor to mount a concentrated wave of attacks on government IT infrastructure systems associated with dozens of organizations across Asia.
Click on any entity below to view its context and source!
industry
Government
Attacks mounted by the threat actor have been found to spike between March and early June 2026, with a "concentrated wave" taking place on June 8 and 9, 2026, targeting dozens of systems associated with government IT infrastructure.
June 8 and 9
Threat actors using the Antino backdoor targeted government and policy organizations across Asia, with a concentrated wave of 57 newly observed endpoints associated with India occurring on June 8 and 9.
Click on any entity below to view its context and source!
infrastructure
57 new endpoints
The largest concentrated wave occurred on June 8 and 9, when Talos identified around 57 newly observed endpoints associated with India.
source_region
India
The largest concentrated wave occurred on June 8 and 9, when Talos identified around 57 newly observed endpoints associated with India.
September 2025
A China-nexus threat cluster designated UAT-11587 has been targeting government and policy organizations across eight Asian countries since September 2025, delivering a previously undocumented Rust-compiled backdoor called Antino.
Click on any entity below to view its context and source!
source_region
China
A China-nexus threat cluster designated UAT-11587 has been targeting government and policy organizations across eight Asian countries since September 2025, delivering a previously undocumented Rust-compiled backdoor called Antino.
industry
Government
A China-nexus threat cluster designated UAT-11587 has been targeting government and policy organizations across eight Asian countries since September 2025, delivering a previously undocumented Rust-compiled backdoor called Antino.
The wider campaign began in September 2025 and targeted government, defense, diplomatic, academic, […] The post Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365 appeared first on Cyber Security News .
Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight Asian countries.
industry
Defense
The wider campaign began in September 2025 and targeted government, defense, diplomatic, academic, […] The post Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365 appeared first on Cyber Security News .
infrastructure
Microsoft 365
The wider campaign began in September 2025 and targeted government, defense, diplomatic, academic, […] The post Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365 appeared first on Cyber Security News .
general_metric
365 services
The wider campaign began in September 2025 and targeted government, defense, diplomatic, academic, […] The post Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365 appeared first on Cyber Security News .
infrastructure
Windows
The wider campaign began in September 2025 and targeted government, defense, diplomatic, academic, […] The post Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365 appeared first on Cyber Security News .
organisation
Cyber Security News
The wider campaign began in September 2025 and targeted government, defense, diplomatic, academic, […] The post Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365 appeared first on Cyber Security News .
target_region
Taiwan, Province of China
The threat actor was first detected in September 2025 in connection with a spear-phishing campaign directed against Taiwan's academic, think tank, and civil society policy community.
tactic
Phishing
The threat actor was first detected in September 2025 in connection with a spear-phishing campaign directed against Taiwan's academic, think tank, and civil society policy community.
tactic
Espionage
Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight Asian countries.
general_metric
16 entities
Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight Asian countries.
2025/10/02
Threat actors associated with UNC6384 used a CloudFront domain to host a JavaScript downloader that targeted government and policy organizations across Asia.
Click on any entity below to view its context and source!
industry
Government
…es.io catering to mainland China
A JavaScript downloader associated with UAT-11587 that references "d32tpl7xt7175h.cloudfront[.]net," a CloudFront domain previously flagged by Arctic Wolf in connection with a campaign conducted by a China-affiliated threat actor known as
UNC6384
targeting European diplomatic and government entities last year using an unpatched Windows shortcut vulnerability.
infrastructure
Windows
…es.io catering to mainland China
A JavaScript downloader associated with UAT-11587 that references "d32tpl7xt7175h.cloudfront[.]net," a CloudFront domain previously flagged by Arctic Wolf in connection with a campaign conducted by a China-affiliated threat actor known as
UNC6384
targeting European diplomatic and government entities last year using an unpatched Windows shortcut vulnerability.
attribution
UNC6384
…es.io catering to mainland China
A JavaScript downloader associated with UAT-11587 that references "d32tpl7xt7175h.cloudfront[.]net," a CloudFront domain previously flagged by Arctic Wolf in connection with a campaign conducted by a China-affiliated threat actor known as
UNC6384
targeting European diplomatic and government entities last year using an unpatched Windows shortcut vulnerability.
January 2026
Threat actors used Antino backdoor to target government and policy organizations across Asia, including a Philippines-focused campaign in January 2026.
Click on any entity below to view its context and source!
target_region
Philippines
In January 2026, the actor conducted two additional Philippines-focused HTML application (HTA) campaigns and began using a broader set of policy and geopolitical lures alongside a standalone fake installer delivery branch.
organisation
HTML
In January 2026, the actor conducted two additional Philippines-focused HTML application (HTA) campaigns and began using a broader set of policy and geopolitical lures alongside a standalone fake installer delivery branch.
organisation
HTA
In January 2026, the actor conducted two additional Philippines-focused HTML application (HTA) campaigns and began using a broader set of policy and geopolitical lures alongside a standalone fake installer delivery branch.
March 2026
Threat actors using UAT-11587's campaign spear-phished Taiwan's academic, think tank, and civil society policy community in March 2026.
Click on any entity below to view its context and source!
tactic
Phishing
Overview
Talos first identified UAT-11587’s campaign while investigating a spear-phishing campaign directed at Taiwan's academic, think tank, and civil society policy community in March 2026.
source_region
Taiwan, Province of China
Overview
Talos first identified UAT-11587’s campaign while investigating a spear-phishing campaign directed at Taiwan's academic, think tank, and civil society policy community in March 2026.
organisation
UAT-11587’s
Overview
Talos first identified UAT-11587’s campaign while investigating a spear-phishing campaign directed at Taiwan's academic, think tank, and civil society policy community in March 2026.
May 2026
Threat actors using the China-nexus UAT-11587 backdoor targeted government and policy organizations across Asia with Antino, later shifting focus to organizations in Syria around May 2026.
Click on any entity below to view its context and source!
target_region
Syrian Arab Republic
Evidence indicates that UAT-11587 has also trained its sights on organizations in Syria around May 2026, indicating a focus beyond Asia.
May 27
Threat actors used Antino backdoor to target government and policy organizations across Asia following a Tehran-based bilateral meeting.
Click on any entity below to view its context and source!
organisation
TPiE
Regional
the May 27 inauguration of the
TPiE
Regional political and civil-society audiences
Tehran_Bilateral_Summit_Proceedings_May2026
Likely diplomatic
, foreign-affairs, or policy audiences following a Tehran-based bilateral meeting.
July 2026
Threat actors using the Antino backdoor targeted at least 16 government and policy organizations across eight Asian countries with espionage activity cluster UAT-11587.
Click on any entity below to view its context and source!
industry
Government
Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight Asian countries.
tactic
Espionage
Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight Asian countries.
general_metric
16 entities
Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight Asian countries.
By July 2026, Talos had identified at least 16 affected or targeted institutional environments across eight Asian countries.
general_metric
10 seconds
By July 2026, Talos had identified at least 10 confirmed and five probable affected institutional environments, plus one additional intended target.
August 2026
Threat actors affiliated with the China-based hackers-for-hire group Jewelbug used Antino backdoor to target government and policy organizations across Asia.
Click on any entity below to view its context and source!
tactic
Espionage
A report published by Broadcom-owned Symantec and Carbon Black in August 2026
characterized
Jewelbug as a China-based hackers-for-hire group that carries out espionage operations and a for-profit cryptocurrency fraud business.
target_region
China
A report published by Broadcom-owned Symantec and Carbon Black in August 2026
characterized
Jewelbug as a China-based hackers-for-hire group that carries out espionage operations and a for-profit cryptocurrency fraud business.
malware
Carbon
A report published by Broadcom-owned Symantec and Carbon Black in August 2026
characterized
Jewelbug as a China-based hackers-for-hire group that carries out espionage operations and a for-profit cryptocurrency fraud business.
between March and early June 2026
Threat actors used Antino backdoor to target government and policy organizations across Asia between March and early June 2026.
Click on any entity below to view its context and source!
industry
Government
Attacks mounted by the threat actor have been found to spike between March and early June 2026, with a "concentrated wave" taking place on June 8 and 9, 2026, targeting dozens of systems associated with government IT infrastructure.
September through November 2025
Threat actors used Philippines-themed lures and direct email attachment delivery to target government and policy organizations across Asia with the China-nexus UAT-11587 malware, which included an Antino backdoor.
Click on any entity below to view its context and source!
target_region
Philippines
The earliest reviewed activity, from September through November 2025, used Philippines-themed lures and direct email attachment delivery.
September 2025 through July 2026
Threat actors used the China-nexus UAT-11587 campaign to target government and policy organizations across Asia with an Antino backdoor from September 2025 through July 2026.
December 2025 to January 2026
Threat actors used the Antino backdoor to target government and policy organizations across Asia during December 2025 to January 2026.
2026/09/30
Threat actors used Antino backdoor to target government and policy organizations across Asia with Microsoft 365 for post-compromise C2.
Click on any entity below to view its context and source!
organisation
Antino Backdoor Uses Outlook
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign.
organisation
OneDrive
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign.
The multi-stage infection chain leverages Cloudflare infrastructure for delivery and deploys Antino, which uniquely uses Microsoft 365 services—specifically Outlook and OneDrive—as dead-drop command-and-control channels rather than traditional C2 servers.
Named Antino, the malware turns Outlook messages and OneDrive files into channels for issuing instructions, moving stolen data, and maintaining access to compromised computers.
Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.”
Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.
organisation
China-Nexus Espionage Campaign
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign.
infrastructure
Microsoft 365
Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel.
Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel
Cisco
Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments.
The multi-stage infection chain leverages Cloudflare infrastructure for delivery and deploys Antino, which uniquely uses Microsoft 365 services—specifically Outlook and OneDrive—as dead-drop command-and-control channels rather than traditional C2 servers.
Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.”
Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.
Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365.
Hackers have built a Windows backdoor that uses Microsoft 365 for all its native command and control communications.
"Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.
Once launched, the Rust-compiled malware communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, instead of depending on a conspicuous dedicated command-and-control (C2) server.
This allows its traffic to blend in with normal Microsoft 365 activity.
Antino communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, rather than depending on a conspicuous dedicated command server.
While the infection chain relied heavily on Cloudflare, Antino itself used Microsoft 365 for post-compromise C2.
…session
and
heartbeat
email drafts; an early DLL already supports OneDrive heartbeats
Stores JSON heartbeat objects under
“
/
antino
/heartbeats/<
session_id
>.
json
”
;
the heartbeat also registers the implant
Dead-drop C2 communication
Antino communicates exclusively through Microsoft 365, using the Microsoft Graph API to interact with Outlook and OneDrive as dead-drop C2 channels.
Both Antino generations use broadly similar Microsoft 365-based C2 workflows.
organisation
Antino Backdoor Lets China-Linked UAT-11587
Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel
Cisco
organisation
Antino
Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments.
"Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence," security researcher Ashley Shen
said
.
Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence.
organisation
CloudFront
During our investigation, Talos also identified a JavaScript downloader associated with UAT-11587 that referenced “d32tpl7xt7175h[.]cloudfront[.]net”, the same CloudFront distribution previously reported by
Arctic Wolf
in China-nexus UNC6384 delivery activity.
organisation
UNC6384
During our investigation, Talos also identified a JavaScript downloader associated with UAT-11587 that referenced “d32tpl7xt7175h[.]cloudfront[.]net”, the same CloudFront distribution previously reported by
Arctic Wolf
in China-nexus UNC6384 delivery activity.
infrastructure
Windows
"Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence," security researcher Ashley Shen
said
.
Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence.
“Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence.
Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365.
Hackers have built a Windows backdoor that uses Microsoft 365 for all its native command and control communications.
"
"The Antino backdoor abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components," Talos said.
Antino is written in Rust and works on both 32-bit and 64-bit versions of Windows.
From that click, a five-stage chain kicks in, leaning on legitimate-looking HTA files, Windows Script Host, and a scripted .NET deserialization trick that abuses a known gadget chain to load malicious code inside a trusted process.
The final stage sideloads Antino through a signed Microsoft diagnostic binary, meaning the thing dropping the backdoor onto disk is a tool Windows itself trusts by default.
Talos also observed WSF stagers that perform the same role through Windows Script Host.
Windows.
Stage 5: Signed-host DLL sideloading Antino backdoor
The downloaded “GatherOsState.exe” is a legitimate Microsoft-signed Windows Assessment and Deployment Kit (ADK) binary that was abused for DLL sideloading.
The Antino backdoor
Antino is a , Rust-compiled Windows backdoor observed in both 32-bit and 64-bit builds.
Talos named the malware after identifying AntinoApp in its Windows application manifest and repeated antino directory names in PDB and Rust source paths across multiple variants.
The Windows application manifest identifies the program as AntinoApp.
D:\a\antino\antino\target\x86_64-pc-windows msvc\release\deps\slc_template.pdb
D:\a\antino\antino\target\x86_64-pc-windows-msvc\release\deps\antino_client_template.pdb
D:\a\antino\antino\target\i686-pc-windows-msvc\release\deps\antino_client_template.pdb
D:\a\antino\antino\client\src\core.rs
D:\a\antino\antino\client\src\signaller\mod.rs
D:\a\antino\antino\client\src\artillery\run.rs
D:\a\antin…
This suggests that the reviewed CI variants were compiled on GitHub-hosted Windows runners.
The cmd and powershell commands allow the operator to execute commands directly through the Windows command shell or PowerShell and collect their output.
Abuse of the Windows Scripted Diagnostics framework workflow
The Antino backdoor abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components.
Program Compatibility Wizard (PCW) troubleshooting package (“C:\Windows\diagnostics\system\PCW”)
Scripted Diagnostics Native Host process (“sdiagnhost.exe”)
Windows
normally uses
“sdiageng.dll” to load troubleshooting packages such as PCW, while “sdiagnhost.exe” executes their PowerShell scripts in a separate process.
The engine creates a temporary working copy of the package and returns its directory, such as “C:\Windows\Temp\SDIAG_<GUID>”.
Antino calls CoCreateInstance to activate the Windows diagnostic COM class.
When set to true, Antino launches its installation task, stages the required files under %LOCALAPPDATA%\Windows GatherOSStateKit\, and creates an HKCU Run value.
organisation
Taiwan Ministry of Finance
UAT-11587 created highly targeted documents that suggest the attackers had researched their victims, including a fake workshop document about Taiwan’s information warfare and a document that closely copied a real Taiwan Ministry of Finance ruling about tax treatment for legislators.
The document exactly reproduces a
public Taiwan Ministry of Finance ruling
to make the decoy appear credible.
organisation
Traditional Chinese
Decoy document metadata carries Simplified Chinese language tags and a UTC+8 timestamp, a combination more consistent with mainland China than Taiwan or Hong Kong, where Traditional Chinese dominates.
However, the combination of the +08:00 offset, the zh-CN language tag and Simplified Chinese metadata is more consistent with a mainland Chinese environment than with Taiwan or Hong Kong,
where Traditional Chinese predominates.
organisation
the “Taiwan Information Warfare
The first decoy described a workshop focused on the “Taiwan Information Warfare.”
infrastructure
350 compromised endpoints
Around 350 compromised endpoints turned up across eight countries, with the largest single wave, roughly 57 new endpoints, hitting India over two days in June.
infrastructure
57 new endpoints
Around 350 compromised endpoints turned up across eight countries, with the largest single wave, roughly 57 new endpoints, hitting India over two days in June.
organisation
SEO
Although Symantec reported that Jewelbug conducted both espionage and cryptocurrency fraud, it assessed that “the SEO business supplied access, delivery and infrastructure into the espionage operation, rather than that one person performed both roles.”
organisation
Cloudflare
The multi-stage infection chain leverages Cloudflare infrastructure for delivery and deploys Antino, which uniquely uses Microsoft 365 services—specifically Outlook and OneDrive—as dead-drop command-and-control channels rather than traditional C2 servers.
The actor relied heavily on Cloudflare infrastructure for delivery, execution tracking, and payload staging.
organisation
Microsoft
The multi-stage infection chain leverages Cloudflare infrastructure for delivery and deploys Antino, which uniquely uses Microsoft 365 services—specifically Outlook and OneDrive—as dead-drop command-and-control channels rather than traditional C2 servers.
Hackers have built a Windows backdoor that uses Microsoft 365 for all its native command and control communications.
This allows its traffic to blend in with normal Microsoft 365 activity.
Antino communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, rather than depending on a conspicuous dedicated command server.
The implant ("slc.dll") is launched by means of DLL sideloading using a legitimate Microsoft-signed binary ("GatherOsState.exe").
organisation
Outlook
The multi-stage infection chain leverages Cloudflare infrastructure for delivery and deploys Antino, which uniquely uses Microsoft 365 services—specifically Outlook and OneDrive—as dead-drop command-and-control channels rather than traditional C2 servers.
Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.”
Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.
"Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.
organisation
Microsoft Graph
Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.”
Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.
"Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.
organisation
Earth Alux
"
UAT-11587 is assessed to share some level of overlap with Jewelbug, which, in turn, exhibits tactical similarities with China-aligned clusters known as CL-STA-0049, Earth Alux, Ink Dragon, and REF7707.
organisation
Outlook for command exchange
It supports host reconnaissance, command execution, persistence, and Microsoft Graph-based C2, using Outlook for command exchange and OneDrive for heartbeat and file transfer.
It can also list running processes, enumerate directories, run PowerShell scripts, shellcode, operator-supplied programs, and commands using "cmd.exe"
For C2, it uses Outlook for command exchange and OneDrive for heartbeat and file transfer.
organisation
DLL
The implant ("slc.dll") is launched by means of DLL sideloading using a legitimate Microsoft-signed binary ("GatherOsState.exe").
It downloads a lure-specific decoy document and a three-file DLL-sideloading bundle from cloud-hosted infrastructure.
organisation
the Windows Scripted Diagnostics
"
"The Antino backdoor abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components," Talos said.
Abuse of the Windows Scripted Diagnostics framework workflow
The Antino backdoor abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components.
organisation
HTA
From that click, a five-stage chain kicks in, leaning on legitimate-looking HTA files, Windows Script Host, and a scripted .NET deserialization trick that abuses a known gadget chain to load malicious code inside a trusted process.
The attack chain itself is a five-stage process that begins with a HTA or WSF stager and culminates in the deployment of Antino.
organisation
Windows Script Host
From that click, a five-stage chain kicks in, leaning on legitimate-looking HTA files, Windows Script Host, and a scripted .NET deserialization trick that abuses a known gadget chain to load malicious code inside a trusted process.
organisation
Windows Assessment and Deployment Kit
Stage 5: Signed-host DLL sideloading Antino backdoor
The downloaded “GatherOsState.exe” is a legitimate Microsoft-signed Windows Assessment and Deployment Kit (ADK) binary that was abused for DLL sideloading.
organisation
AntinoApp
Talos named the malware after identifying AntinoApp in its Windows application manifest and repeated antino directory names in PDB and Rust source paths across multiple variants.
organisation
PDB
Talos named the malware after identifying AntinoApp in its Windows application manifest and repeated antino directory names in PDB and Rust source paths across multiple variants.
organisation
CI
This suggests that the reviewed CI variants were compiled on GitHub-hosted Windows runners.
organisation
PCW
Program Compatibility Wizard (PCW) troubleshooting package (“C:\Windows\diagnostics\system\PCW”)
Scripted Diagnostics Native Host process (“sdiagnhost.exe”)
Windows
normally uses
“sdiageng.dll” to load troubleshooting packages such as PCW, while “sdiagnhost.exe” executes their PowerShell scripts in a separate process.
organisation
Cloudflare R2
The actor uses two cloud services to deliver the second-stage JavaScript:
Cloudflare R2: “pub-<32-character hexadecimal identifier>[.]r2[.]dev”
Amazon CloudFront: “d2nq35tel3ucuo[.]cloudfront[.]net”
The fixed Cloudflare Pages hostname “oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev” appears across multiple reviewed HTA variants.
organisation
Registry
"This can complicate behavioral attribution to the original implant, although it does not eliminate observable PowerShell, file-creation, or Registry telemetry."
organisation
HTML
"Another social engineering technique used for initial access in this campaign was the closely replicated reconstruction of Gmail's native attachment preview widget inside the email HTML body," Shen explained.
Open the email in Gmail and it looks just like the real thing because Gmail simply renders the HTML it receives.
organisation
PE
In this case, the gadget chain loads the embedded PE file, “TestAssembly.dll”, directly into memory and executes it inside mshta.exe.
organisation
PNG
"The actor replicated the styling of Gmail's attachment card using four inline PNG images embedded as Base64-encoded MIME parts."
"The entire attachment card was wrapped in an anchor tag pointing to an attacker-controlled [Cloudflare Pages] URL.
The actor replicated the styling of Gmail’s attachment card using four inline PNG images embedded as Base64-encoded MIME parts.
organisation
MIME
"The actor replicated the styling of Gmail's attachment card using four inline PNG images embedded as Base64-encoded MIME parts."
"The entire attachment card was wrapped in an anchor tag pointing to an attacker-controlled [Cloudflare Pages] URL.
The actor replicated the styling of Gmail’s attachment card using four inline PNG images embedded as Base64-encoded MIME parts.
organisation
Cloudflare Pages
"The actor replicated the styling of Gmail's attachment card using four inline PNG images embedded as Base64-encoded MIME parts."
"The entire attachment card was wrapped in an anchor tag pointing to an attacker-controlled [Cloudflare Pages] URL.
Cloudflare Pages, R2, and Amazon CloudFront carried almost every stage of this, which kept the traffic blending into ordinary HTTPS the whole way through.
These links use Cloudflare Pages URLs with the pattern shown below.
organisation
Amazon CloudFront
Cloudflare Pages, R2, and Amazon CloudFront carried almost every stage of this, which kept the traffic blending into ordinary HTTPS the whole way through.
BinaryFormatter deserialization chain
The three files downloaded from Cloudflare R2 or Amazon CloudFront are the JScript orchestrator and two serialized .NET gadget resources.
organisation
Associated Press
In another case, the attackers reused a real Associated Press story about alleged Russian offers to the US over Venezuela.
“Trump’s Former Russia Adviser Claims Moscow Offered US Free Rein in Venezuela in Exchange for Ukraine” closely paraphrased an
Associated Press report
, with two related samples appearing on VirusTotal two days later.
organisation
VirusTotal
“Trump’s Former Russia Adviser Claims Moscow Offered US Free Rein in Venezuela in Exchange for Ukraine” closely paraphrased an
Associated Press report
, with two related samples appearing on VirusTotal two days later.
Matching malware samples appeared on VirusTotal two days after the original article was published.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Antino backdoor)
organisation
JScript
Stage 2: HTA-hosted JScript downloader and decryptor
The Stage 2 component is HTA-hosted Microsoft JScript, delivered from Cloudflare R2 and loaded in-process by mshta.exe through the HTA stager.
organisation
Microsoft JScript
Stage 2: HTA-hosted JScript downloader and decryptor
The Stage 2 component is HTA-hosted Microsoft JScript, delivered from Cloudflare R2 and loaded in-process by mshta.exe through the HTA stager.
organisation
hxxps://microsoft-flash[.]com
…my-u0up9qri[.]pages[.]dev (Cloudflare Pages delivery domain)
my-vtsdod2n[.]pages[.]dev (Cloudflare Pages delivery domain)
my-wgoxp32b[.]pages[.]dev (Cloudflare Pages delivery domain)
microsoft-flash[.]com (standalone Antino fake-installer delivery domain)
wps-cn[.]com (standalone Antino fake-installer delivery domain)
hxxps://microsoft-flash[.]com/download/flashcenter_pp_ax_install_en.exe
organisation
IP
…b76db549682a183c5a186df4bb (Antino Gen 2 slc.dll backdoor)
fdbd047031c13a17c9f491c9355f44d587584ebe2b8927be8482e6c236c8e1c1 (Antino Gen 2 slc.dll backdoor)
103[.]27[.]110[.]220 (historical serving IP for the Antino payload hosted on wps-cn[.]com)
osc-cdn[.]com (actor-used spear-phishing sender domain)
oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev (Cloudflare Pages execution-tracking doma…
organisation
osc-cdn[.]com
…ckdoor)
fdbd047031c13a17c9f491c9355f44d587584ebe2b8927be8482e6c236c8e1c1 (Antino Gen 2 slc.dll backdoor)
103[.]27[.]110[.]220 (historical serving IP for the Antino payload hosted on wps-cn[.]com)
osc-cdn[.]com (actor-used spear-phishing sender domain)
oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev (Cloudflare Pages execution-tracking domain)
d2nq35tel3ucuo[.]cloudfront[.]net (Antino-chai…
organisation
microsoft-flash[.]com
…ery domain)
my-u0up9qri[.]pages[.]dev (Cloudflare Pages delivery domain)
my-vtsdod2n[.]pages[.]dev (Cloudflare Pages delivery domain)
my-wgoxp32b[.]pages[.]dev (Cloudflare Pages delivery domain)
microsoft-flash[.]com (standalone Antino fake-installer delivery domain)
wps-cn[.]com (standalone Antino fake-installer delivery domain)
hxxps://microsoft-flash[.]com/download/flashcenter_pp_ax_ins…
infrastructure
2 standalone installer backdoor
b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e (Antino Gen 2 standalone fake-installer backdoor)
ca14ad0344dc7216f6da29a5cbe4237d886cc5257e8c3a48fb4885a311c9b800 (post-unpack Antino standalone backdoor memory image)
e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 (Antino Gen 2 slc.dll backdoor)
e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb…
(Antino-chain TestAssembly.dll downloader)
131ac3e0df777910e0a32e43d5744bccb0490750d4c2adc359da41d76d383c46 (Antino-chain TestAssembly.dll downloader)
09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff (Antino Gen 2 slc.dll backdoor)
0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd (Antino Gen 2 standalone fake-installer backdoor)
1fadc90b61ce536abda78eb387a7f3d7…
5c5c060b272cd4a5c3767edc0e9478bd35b7e1756e183d0446a5491bd65519cb (configured Antino standalone backdoor)
971cb2448b5d67dcc1f5eaa10d12e77f213035ad31230dc2ac7a510610a2059d (Antino Gen 2 standalone fake-installer backdoor)
9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 (Antino Gen 2 standalone fake-installer backdoor)
organisation
Stage 2
65f4b9292e91abfa5adf42a03526932930c1c0a436bb186a7948fe6770295788 (malicious WSF stager - internal-review lure)
61a8f5add6c35f99c389012dbb2343061fd0b54611b40490b9a7f0b49d707da0 (Antino-chain Stage 2 JScript downloader and decryptor)
organisation
UUID
Generates a random UUID v4
containing
no host-derived information
Registration and heartbeat
Classic builds use
sendsession
and
heartbeat
email drafts; an early DLL already supports OneDrive heartbeats
Stores JSON heartbeat objects under
“
/
antino
/heartbeats/<
session_id
>.
json
”
;
the heartbeat also registers the implant
Dead-drop C2 communication
Antino communicates exclu…
organisation
The Scripted Diagnostics
The Scripted Diagnostics engine delegates execution to the native host, observed in runtime traces as %windir%\SysWOW64\sdiagnhost.exe -Embedding.
organisation
SMTP
The actor exploited the distinction between the SMTP envelope sender and the visible From header.
organisation
DMARC
The receiving provider therefore accepted the message, allowing the spoofed email to be successfully delivered to the recipient’s inbox despite the DMARC failure.
organisation
TikTok
The document referenced a 2025 TikTok study and discussed perceived public knowledge gaps concerning cross-strait issues and information manipulation.
organisation
Indo-Pacific
Indo-Pacific policy-themed decoy document.
organisation
BinaryFormatter
Later stages abuse unsafe BinaryFormatter deserialization and gadget chains in standard .NET assemblies to load and execute the final payload.
organisation
TestAssembly
.NET assembly metadata for the TestAssembly component.
organisation
Entra ID
This authentication method allows the registered Entra ID application to access the configured Outlook mailbox and OneDrive resources without requiring an interactive user sign-in.
organisation
request_id
It has three fields: command_type, the command to invoke; command_data, an object containing command-specific parameters; and request_id, a per-command identifier used to correlate the request with the corresponding response (the request_id is distinct from the implant session_id used in the message subject and heartbeat).
organisation
VirtualAlloc
When enabled, Antino hooks Sleep and VirtualAlloc and registers a vectored exception handler (VEH).
organisation
VEH
When enabled, Antino hooks Sleep and VirtualAlloc and registers a vectored exception handler (VEH).
organisation
add_to_run
Both the execute_program and add_to_run commands use this technique.
organisation
ClamAV
The following ClamAV signatures detect and blocks this threat:
Html.
organisation
Snort
UAT-11587-10060384-1
The following Snort rules cover this threat:
financial
2 Txt
UAT-11587-10060367-2
Txt.Trojan.
financial
5 Txt
UAT-11587-10060385-5
Txt.Trojan.
financial
1 Win
UAT-11587-10060386-1
Win.
UAT-11587-10060365-1
Win.
UAT-11587-10060366-1
Win.
UAT-11587-10060370-1
Win.
UAT-11587-10060371-1
Win.
UAT-11587-10060373-1
Win.
UAT-11587-10060374-1
Win.
UAT-11587-10060375-1
Win.
UAT-11587-10060378-1
Win.
UAT-11587-10060379-1
Win.
UAT-11587-10060380-1
Win.
Tactical Metrics
Metrics
infrastructure
Microsoft 365
Affected Product
Click for context!
The multi-stage infection chain leverages Cloudflare infrastructure for delivery and deploys Antino, which uniquely uses Microsoft 365 services—specifically Outlook and OneDrive—as dead-drop command-and-control channels rather than traditional C2 servers.
The wider campaign began in September 2025 and targeted government, defense, diplomatic, academic, […] The post Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365 appeared first on Cyber Security News .
Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365.
Hackers have built a Windows backdoor that uses Microsoft 365 for all its native command and control communications.
"Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.
Once launched, the Rust-compiled malware communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, instead of depending on a conspicuous dedicated command-and-control (C2) server.
Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel.
Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel
Cisco
Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments.
Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.”
This allows its traffic to blend in with normal Microsoft 365 activity.
Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.
Antino communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, rather than depending on a conspicuous dedicated command server.
While the infection chain relied heavily on Cloudflare, Antino itself used Microsoft 365 for post-compromise C2.
…session
and
heartbeat
email drafts; an early DLL already supports OneDrive heartbeats
Stores JSON heartbeat objects under
“
/
antino
/heartbeats/<
session_id
>.
json
”
;
the heartbeat also registers the implant
Dead-drop C2 communication
Antino communicates exclusively through Microsoft 365, using the Microsoft Graph API to interact with Outlook and OneDrive as dead-drop C2 channels.
Both Antino generations use broadly similar Microsoft 365-based C2 workflows.
Metrics
infrastructure
Windows
Affected Product
The wider campaign began in September 2025 and targeted government, defense, diplomatic, academic, […] The post Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365 appeared first on Cyber Security News .
Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365.
Hackers have built a Windows backdoor that uses Microsoft 365 for all its native command and control communications.
…es.io catering to mainland China
A JavaScript downloader associated with UAT-11587 that references "d32tpl7xt7175h.cloudfront[.]net," a CloudFront domain previously flagged by Arctic Wolf in connection with a campaign conducted by a China-affiliated threat actor known as
UNC6384
targeting European diplomatic and government entities last year using an unpatched Windows shortcut vulnerability.
"Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence," security researcher Ashley Shen
said
.
"
"The Antino backdoor abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components," Talos said.
“Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence.
Antino is written in Rust and works on both 32-bit and 64-bit versions of Windows.
From that click, a five-stage chain kicks in, leaning on legitimate-looking HTA files, Windows Script Host, and a scripted .NET deserialization trick that abuses a known gadget chain to load malicious code inside a trusted process.
The final stage sideloads Antino through a signed Microsoft diagnostic binary, meaning the thing dropping the backdoor onto disk is a tool Windows itself trusts by default.
Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence.
Talos also observed WSF stagers that perform the same role through Windows Script Host.
Windows.
Stage 5: Signed-host DLL sideloading Antino backdoor
The downloaded “GatherOsState.exe” is a legitimate Microsoft-signed Windows Assessment and Deployment Kit (ADK) binary that was abused for DLL sideloading.
The Antino backdoor
Antino is a , Rust-compiled Windows backdoor observed in both 32-bit and 64-bit builds.
Talos named the malware after identifying AntinoApp in its Windows application manifest and repeated antino directory names in PDB and Rust source paths across multiple variants.
The Windows application manifest identifies the program as AntinoApp.
D:\a\antino\antino\target\x86_64-pc-windows msvc\release\deps\slc_template.pdb
D:\a\antino\antino\target\x86_64-pc-windows-msvc\release\deps\antino_client_template.pdb
D:\a\antino\antino\target\i686-pc-windows-msvc\release\deps\antino_client_template.pdb
D:\a\antino\antino\client\src\core.rs
D:\a\antino\antino\client\src\signaller\mod.rs
D:\a\antino\antino\client\src\artillery\run.rs
D:\a\antin…
This suggests that the reviewed CI variants were compiled on GitHub-hosted Windows runners.
The cmd and powershell commands allow the operator to execute commands directly through the Windows command shell or PowerShell and collect their output.
Abuse of the Windows Scripted Diagnostics framework workflow
The Antino backdoor abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components.
Program Compatibility Wizard (PCW) troubleshooting package (“C:\Windows\diagnostics\system\PCW”)
Scripted Diagnostics Native Host process (“sdiagnhost.exe”)
Windows
normally uses
“sdiageng.dll” to load troubleshooting packages such as PCW, while “sdiagnhost.exe” executes their PowerShell scripts in a separate process.
The engine creates a temporary working copy of the package and returns its directory, such as “C:\Windows\Temp\SDIAG_<GUID>”.
Antino calls CoCreateInstance to activate the Windows diagnostic COM class.
When set to true, Antino launches its installation task, stages the required files under %LOCALAPPDATA%\Windows GatherOSStateKit\, and creates an HKCU Run value.
Metrics
infrastructure
350
Compromised Endpoints
Around 350 compromised endpoints turned up across eight countries, with the largest single wave, roughly 57 new endpoints, hitting India over two days in June.
Metrics
infrastructure
57
New Endpoints
Around 350 compromised endpoints turned up across eight countries, with the largest single wave, roughly 57 new endpoints, hitting India over two days in June.
The largest concentrated wave occurred on June 8 and 9, when Talos identified around 57 newly observed endpoints associated with India.
Metrics
infrastructure
2
Standalone Installer Backdoor
b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e (Antino Gen 2 standalone fake-installer backdoor)
ca14ad0344dc7216f6da29a5cbe4237d886cc5257e8c3a48fb4885a311c9b800 (post-unpack Antino standalone backdoor memory image)
e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 (Antino Gen 2 slc.dll backdoor)
e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb…
(Antino-chain TestAssembly.dll downloader)
131ac3e0df777910e0a32e43d5744bccb0490750d4c2adc359da41d76d383c46 (Antino-chain TestAssembly.dll downloader)
09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff (Antino Gen 2 slc.dll backdoor)
0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd (Antino Gen 2 standalone fake-installer backdoor)
1fadc90b61ce536abda78eb387a7f3d7…
5c5c060b272cd4a5c3767edc0e9478bd35b7e1756e183d0446a5491bd65519cb (configured Antino standalone backdoor)
971cb2448b5d67dcc1f5eaa10d12e77f213035ad31230dc2ac7a510610a2059d (Antino Gen 2 standalone fake-installer backdoor)
9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 (Antino Gen 2 standalone fake-installer backdoor)
Metrics
financial
2
Txt
UAT-11587-10060367-2
Txt.Trojan.
Metrics
financial
5
Txt
UAT-11587-10060385-5
Txt.Trojan.
Metrics
financial
1
Win
UAT-11587-10060386-1
Win.
UAT-11587-10060365-1
Win.
UAT-11587-10060366-1
Win.
UAT-11587-10060370-1
Win.
UAT-11587-10060371-1
Win.
UAT-11587-10060373-1
Win.
UAT-11587-10060374-1
Win.
UAT-11587-10060375-1
Win.
UAT-11587-10060378-1
Win.
UAT-11587-10060379-1
Win.
UAT-11587-10060380-1
Win.
Intelligence Sources
AlienVault OTX
2026-10-01
Security Affairs
2026-10-03
The Hacker News
2026-10-02
AlienVault OTX
2026-09-30
Talos Intelligence
2026-09-30
AlienVault OTX
2026-10-02
AlienVault OTX
2026-09-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T11:55
Comprehensive Tactical Telemetry
Highly Correlated Entities
79x
organisation
Identified Entity
Antino
entity
18x
timeline
Temporal Reference
September 2025
date
16x
target region
Target Country
Taiwan, Province of China
country
11x
general metric
Uat-11587 Win
10,060,366
uat-11587 win
9x
general metric
Uat-11587
10,060,384
uat-11587
8x
attribution
Attributing Entity
Antino
authority
7x
industry
Targeted Sector
Government
sector
5x
source region
Origin Country
China
country
5x
tactic
Cyber Operation Type
Espionage
tactic
3x
general metric
Stage
4
stage
2x
infrastructure
Affected Product
Microsoft 365
software
2x
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
2x
general metric
Bit
32
bit
2x
financial
Txt
2
txt
Contextual Telemetry
Context Block
15 METRICS
general metric
Services
365
services
malware
Malware Payload
Carbon
tool
general metric
Entities
16
entities
general metric
Seconds
10
seconds
infrastructure
Compromised Endpoints
350
compromised endpoints
infrastructure
New Endpoints
57
new endpoints
general metric
Csis Indo Pacific Forecast
2,026
csis indo pacific forecast
infrastructure
Standalone Installer Backdoor
2
standalone installer backdoor
general metric
Antino Gen
2
antino gen
general metric
Guid
1,669
guid
general metric
Gen
1
gen
general metric
Investigation
350
investigation
general metric
Body
20
body
general metric
Value
22
value
financial
Win
1
win
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.