Skip to main content

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

0
High
Published: 09/30/2026 (09/30/2026, 10:00:01 UTC)
Source: Cisco Talos

Description

Cisco Talos identified a China-nexus cyber espionage campaign named UAT-11587 targeting government and policy organizations across Asia, including Taiwan, India, the Philippines, and Cambodia. The campaign uses spear-phishing emails with tailored decoy documents to deliver a Rust-compiled Windows backdoor called Antino. Antino supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading, and persistence. Its command-and-control communication uniquely operates through Microsoft 365 applications using Microsoft Graph to interact with Outlook and OneDrive. The campaign has affected at least 16 institutional environments across eight Asian countries with approximately 350 compromised endpoints. Talos assesses this activity as an intelligence gathering operation with moderate to high confidence. No patch or remediation guidance is provided in the report.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/30/2026, 10:09:21 UTC

Technical Analysis

UAT-11587 is a China-nexus cyber espionage campaign uncovered by Cisco Talos that targets government and policy organizations across multiple Asian countries. The threat actor uses spear-phishing emails with customized decoy documents to initiate a multi-stage infection chain culminating in the deployment of Antino, a previously undocumented Rust-compiled Windows backdoor. Antino enables extensive post-compromise capabilities including host reconnaissance, shell and PowerShell command execution, file transfer, in-memory shellcode loading, and persistence. Its command-and-control channel is novel in that it exclusively leverages Microsoft 365 services, specifically Microsoft Graph API interactions with Outlook and OneDrive objects, to evade detection by avoiding traditional dedicated C2 servers. The campaign has been active from September 2025 through July 2026, impacting at least 16 institutional environments and approximately 350 endpoints across eight Asian countries. Talos attributes the campaign to a China-nexus actor with high confidence based on technical and operational indicators such as decoy document metadata, use of a China-focused Rust package mirror, and infrastructure overlaps. The campaign focuses on intelligence gathering from defense, government, diplomatic, security, and policy research sectors. No known exploits in the wild or vendor patches are reported.

Potential Impact

The campaign enables persistent unauthorized access to targeted government and policy organizations across Asia, facilitating espionage through host reconnaissance, command execution, file transfers, and in-memory code loading. The use of Microsoft 365 as a covert command-and-control channel complicates detection and mitigation efforts. Approximately 350 endpoints across eight countries have been compromised, potentially exposing sensitive national security and policy information. The campaign's targeting of critical public-sector and national security-adjacent organizations indicates a significant impact on regional intelligence and security.

Defensive Guidance

No official patch or remediation guidance is provided in the available information. Organizations should be aware of the spear-phishing delivery vector and the novel use of Microsoft 365 services for command-and-control. Mitigation should focus on enhancing email security to detect and block spear-phishing attempts, monitoring for unusual Microsoft 365 API activity, and applying threat intelligence to identify indicators of compromise related to Antino and UAT-11587. Since this is a targeted espionage campaign, tailored detection and response strategies are recommended. Patch status is not yet confirmed — check vendor advisories and threat intelligence updates for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.74,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/","fetched":true,"fetchedAt":"2026-09-30T10:09:13.761Z","wordCount":5483}

Threat ID: 6abcdfc90df196e1a9dc7315

Added to database: 09/30/2026, 10:09:13 UTC

Last enriched: 09/30/2026, 10:09:21 UTC

Last updated: 09/30/2026, 12:28:45 UTC

Views: 16

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses