Adversary Intelligence — 2026-10-06

China-Nexus UAT-11587 Espionage Campaign Deploys Antino Backdoor Against Asian Government Organizations

BLUFAntino's use of legitimate Microsoft 365 channels for command and control lets implants persist inside enterprise allowlists, and undetected footholds across affected Asian government networks may remain active.

Cisco Talos, in a report published September 30, traced UAT-11587 activity from September 2025 through July 2026 and assessed with high confidence that the actor is China-nexus 12. eSecurity Planet's summary of that report says Talos found about 350 compromised endpoints across eight countries, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria 1. The Hacker News lists seven of those countries and omits Syria 3. Per the same account, targets included defense, diplomatic, law enforcement and legislative bodies, universities and think tanks 1. Talos reported that the previously undocumented Rust backdoor Antino arrives via spear-phishing and runs command and control through Microsoft Graph, using Outlook for commands and OneDrive for heartbeats and file exfiltration 14. Talos did not attribute the actor to a specific Chinese agency 1.

Analysis
Defenders in Asian government, diplomatic and policy bodies should treat Microsoft Graph traffic from unexpected process trees as a live intrusion indicator, since Antino hides command and control in Outlook and OneDrive sessions that enterprise allowlists permit. Everything traces to one Cisco Talos report, which attributes the actor to China-nexus activity but names no specific agency, and other outlets only amplify it. Collection against defense, diplomatic and legislative targets points to intelligence gathering. Nothing shows the operation ended in July, so undetected implants remain possible. The roughly 350 endpoints may overstate coordinated state tasking, since a regional contractor or several loosely linked operators could have run overlapping campaigns that Talos grouped together.
5 sources
  1. China-Linked Hackers Target Asian Governments With Antino Backdoor - eSecurity Planet
  2. UAT-11587 Antino Backdoor - SecurityOnline
  3. Antino Backdoor Uses Outlook and OneDrive for C2 in China-Linked Campaign Against Asian Governments - The Hacker News
  4. 5th October Threat Intelligence Report - Check Point Research
  5. China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor - Cisco Talos

View in full brief →

UNCLASSIFIED // OPEN SOURCE