China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos identified a China-nexus cyber espionage campaign named UAT-11587 targeting government and policy organizations across Asia, including Taiwan, India, the Philippines, and Cambodia. The campaign uses spear-phishing emails with tailored decoy documents to deliver a Rust-compiled Windows backdoor called Antino. Antino supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading, and persistence. Its command-and-control communication uniquely operates through Microsoft 365 applications using Microsoft Graph to interact with Outlook and OneDrive. The campaign has affected at least 16 institutional environments across eight Asian countries with approximately 350 compromised endpoints. Talos assesses this activity as an intelligence gathering operation with moderate to high confidence. No patch or remediation guidance is provided in the report.
AI Analysis
Technical Summary
UAT-11587 is a China-nexus cyber espionage campaign uncovered by Cisco Talos that targets government and policy organizations across multiple Asian countries. The threat actor uses spear-phishing emails with customized decoy documents to initiate a multi-stage infection chain culminating in the deployment of Antino, a previously undocumented Rust-compiled Windows backdoor. Antino enables extensive post-compromise capabilities including host reconnaissance, shell and PowerShell command execution, file transfer, in-memory shellcode loading, and persistence. Its command-and-control channel is novel in that it exclusively leverages Microsoft 365 services, specifically Microsoft Graph API interactions with Outlook and OneDrive objects, to evade detection by avoiding traditional dedicated C2 servers. The campaign has been active from September 2025 through July 2026, impacting at least 16 institutional environments and approximately 350 endpoints across eight Asian countries. Talos attributes the campaign to a China-nexus actor with high confidence based on technical and operational indicators such as decoy document metadata, use of a China-focused Rust package mirror, and infrastructure overlaps. The campaign focuses on intelligence gathering from defense, government, diplomatic, security, and policy research sectors. No known exploits in the wild or vendor patches are reported.
Potential Impact
The campaign enables persistent unauthorized access to targeted government and policy organizations across Asia, facilitating espionage through host reconnaissance, command execution, file transfers, and in-memory code loading. The use of Microsoft 365 as a covert command-and-control channel complicates detection and mitigation efforts. Approximately 350 endpoints across eight countries have been compromised, potentially exposing sensitive national security and policy information. The campaign's targeting of critical public-sector and national security-adjacent organizations indicates a significant impact on regional intelligence and security.
Mitigation Recommendations
No official patch or remediation guidance is provided in the available information. Organizations should be aware of the spear-phishing delivery vector and the novel use of Microsoft 365 services for command-and-control. Mitigation should focus on enhancing email security to detect and block spear-phishing attempts, monitoring for unusual Microsoft 365 API activity, and applying threat intelligence to identify indicators of compromise related to Antino and UAT-11587. Since this is a targeted espionage campaign, tailored detection and response strategies are recommended. Patch status is not yet confirmed — check vendor advisories and threat intelligence updates for current remediation guidance.
Affected Countries
Taiwan, India, Philippines, Cambodia, Pakistan, Thailand, Myanmar, Syria
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Description
Cisco Talos identified a China-nexus cyber espionage campaign named UAT-11587 targeting government and policy organizations across Asia, including Taiwan, India, the Philippines, and Cambodia. The campaign uses spear-phishing emails with tailored decoy documents to deliver a Rust-compiled Windows backdoor called Antino. Antino supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading, and persistence. Its command-and-control communication uniquely operates through Microsoft 365 applications using Microsoft Graph to interact with Outlook and OneDrive. The campaign has affected at least 16 institutional environments across eight Asian countries with approximately 350 compromised endpoints. Talos assesses this activity as an intelligence gathering operation with moderate to high confidence. No patch or remediation guidance is provided in the report.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
UAT-11587 is a China-nexus cyber espionage campaign uncovered by Cisco Talos that targets government and policy organizations across multiple Asian countries. The threat actor uses spear-phishing emails with customized decoy documents to initiate a multi-stage infection chain culminating in the deployment of Antino, a previously undocumented Rust-compiled Windows backdoor. Antino enables extensive post-compromise capabilities including host reconnaissance, shell and PowerShell command execution, file transfer, in-memory shellcode loading, and persistence. Its command-and-control channel is novel in that it exclusively leverages Microsoft 365 services, specifically Microsoft Graph API interactions with Outlook and OneDrive objects, to evade detection by avoiding traditional dedicated C2 servers. The campaign has been active from September 2025 through July 2026, impacting at least 16 institutional environments and approximately 350 endpoints across eight Asian countries. Talos attributes the campaign to a China-nexus actor with high confidence based on technical and operational indicators such as decoy document metadata, use of a China-focused Rust package mirror, and infrastructure overlaps. The campaign focuses on intelligence gathering from defense, government, diplomatic, security, and policy research sectors. No known exploits in the wild or vendor patches are reported.
Potential Impact
The campaign enables persistent unauthorized access to targeted government and policy organizations across Asia, facilitating espionage through host reconnaissance, command execution, file transfers, and in-memory code loading. The use of Microsoft 365 as a covert command-and-control channel complicates detection and mitigation efforts. Approximately 350 endpoints across eight countries have been compromised, potentially exposing sensitive national security and policy information. The campaign's targeting of critical public-sector and national security-adjacent organizations indicates a significant impact on regional intelligence and security.
Defensive Guidance
No official patch or remediation guidance is provided in the available information. Organizations should be aware of the spear-phishing delivery vector and the novel use of Microsoft 365 services for command-and-control. Mitigation should focus on enhancing email security to detect and block spear-phishing attempts, monitoring for unusual Microsoft 365 API activity, and applying threat intelligence to identify indicators of compromise related to Antino and UAT-11587. Since this is a targeted espionage campaign, tailored detection and response strategies are recommended. Patch status is not yet confirmed — check vendor advisories and threat intelligence updates for current remediation guidance.
Technical Details
- Classification
- {"confidence":0.74,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/","fetched":true,"fetchedAt":"2026-09-30T10:09:13.761Z","wordCount":5483}
Threat ID: 6abcdfc90df196e1a9dc7315
Added to database: 09/30/2026, 10:09:13 UTC
Last enriched: 09/30/2026, 10:09:21 UTC
Last updated: 09/30/2026, 12:28:45 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.