Blog.Talosintelligence China-Nexus UAT-11587 Campaign Uses Antino Backdoor Across Asia
Article Content
- •UAT-11587 targets government organizations across eight Asian countries.
- •The Antino backdoor uses Microsoft 365 for covert command-and-control operations.
- •Spear-phishing emails are the primary attack vector, employing tailored decoy documents.
Cisco Talos has identified a cyberespionage campaign, tracked as UAT-11587, linked to a China-nexus threat actor targeting government and policy organizations across eight Asian countries. The campaign, which began in September 2025, has deployed a previously undocumented Rust-compiled backdoor named Antino, utilizing Microsoft 365 services for command-and-control communications. Targets include entities in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria, with at least 16 organizations confirmed affected. The attack vector primarily involves spear-phishing emails that spoof trusted senders, leading to a multi-stage infection process. Antino supports various malicious functionalities, including shell access and file transfers, while blending its traffic with legitimate Microsoft 365 activity. The campaign has shown significant activity spikes, particularly between March and June 2026, with a notable wave of attacks on June 8-9. Talos assesses the threat actor with high confidence as being linked to China based on technical indicators and operational patterns.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Antino and Outlook in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which countries are affected?
How does the Antino backdoor operate?
What should organizations do to protect themselves?
Continue Reading
Critical RCE Vulnerabilities in GitLab and Dell; Warlock Ransomware Targets SharePoint GitLab and Dell released critical patches for remote code execution vulnerabilities on October 3, 2026. GitLab's AI Gateway vulnerability (CVE-2026-90970) allows arbitrary command execution on self-hosted instances, with a CVSS score of 9.9. Dell's Container Storage Modules have critical flaws (CVSS 10.0) enabling…
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…