Skip to content
China-Nexus UAT-11587 Campaign Uses Antino Backdoor Across Asia

China-Nexus UAT-11587 Campaign Uses Antino Backdoor Across Asia

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •UAT-11587 targets government organizations across eight Asian countries.
  • •The Antino backdoor uses Microsoft 365 for covert command-and-control operations.
  • •Spear-phishing emails are the primary attack vector, employing tailored decoy documents.

Cisco Talos has identified a cyberespionage campaign, tracked as UAT-11587, linked to a China-nexus threat actor targeting government and policy organizations across eight Asian countries. The campaign, which began in September 2025, has deployed a previously undocumented Rust-compiled backdoor named Antino, utilizing Microsoft 365 services for command-and-control communications. Targets include entities in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria, with at least 16 organizations confirmed affected. The attack vector primarily involves spear-phishing emails that spoof trusted senders, leading to a multi-stage infection process. Antino supports various malicious functionalities, including shell access and file transfers, while blending its traffic with legitimate Microsoft 365 activity. The campaign has shown significant activity spikes, particularly between March and June 2026, with a notable wave of attacks on June 8-9. Talos assesses the threat actor with high confidence as being linked to China based on technical indicators and operational patterns.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-09-01
UAT-11587 campaign begins
Cisco Talos first observed UAT-11587 activity targeting government entities.
Blog.Talosintelligence
2026-03-01
Spear-phishing campaign identified
Talos identified spear-phishing emails targeting Taiwan's academic and policy community.
Esecurityplanet
2026-06-08
Major attack wave observed
Talos reported a concentrated wave of attacks with 57 new endpoints identified in India.
Esecurityplanet
2026-09-30
Talos report published
Cisco Talos released a detailed report on UAT-11587 and the Antino backdoor.
Blog.Talosintelligence

More articles in this cluster (6)

Following this threat?

Track Antino and Outlook in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which countries are affected?
The campaign has targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria.
How does the Antino backdoor operate?
Antino uses Microsoft 365 services for command-and-control communications, polling Outlook for commands and using OneDrive for data exfiltration.
What should organizations do to protect themselves?
Organizations should implement robust email filtering, monitor for suspicious activity, and educate employees about phishing threats.