China-Nexus UAT-11587 Espionage Campaign Deploys Antino Backdoor Against Asian Government Organizations
Defenders in Asian government, diplomatic and policy bodies should treat Microsoft Graph traffic from unexpected process trees as a live intrusion indicator, since Antino hides command and control in Outlook and OneDrive sessions that enterprise allowlists permit. Everything traces to one Cisco Talos report, which attributes the actor to China-nexus activity but names no specific agency, and other outlets only amplify it. Collection against defense, diplomatic and legislative targets points to intelligence gathering. Nothing shows the operation ended in July, so undetected implants remain possible. The roughly 350 endpoints may overstate coordinated state tasking, since a regional contractor or several loosely linked operators could have run overlapping campaigns that Talos grouped together.
5 sources
- China-Linked Hackers Target Asian Governments With Antino Backdoor -
eSecurity Planet - UAT-11587 Antino Backdoor -
SecurityOnline - Antino Backdoor Uses Outlook and OneDrive for C2 in China-Linked Campaign Against Asian Governments -
The Hacker News - 5th October Threat Intelligence Report -
Check Point Research - China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor -
Cisco Talos