Skip to content
China-Nexus UAT-11587 Uses Antino Backdoor for Cyber-Espionage

China-Nexus UAT-11587 Uses Antino Backdoor for Cyber-Espionage

First seen 4 Oct 2026, 16:05 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 17:02 UTC
  • •UAT-11587 targets government and policy organizations in Asia and the Middle East.
  • •The Antino backdoor uses Microsoft 365 services for stealthy command-and-control.
  • •Advanced techniques like DLL sideloading and social engineering are employed.

A newly identified cyber-espionage campaign attributed to the China-nexus group UAT-11587 is actively exploiting Microsoft 365 services, specifically Outlook and OneDrive, to deploy the Antino backdoor. This sophisticated attack targets government and policy organizations across Asia and the Middle East. The campaign utilizes multi-stage infection chains, including spear-phishing emails that deliver malicious payloads via trusted cloud services. The Antino backdoor, developed in Rust, allows for stealthy command-and-control operations by embedding malicious traffic within legitimate cloud activity. The threat actor employs advanced techniques such as DLL sideloading and social engineering to evade detection. Current mitigation strategies are being discussed to counteract this ongoing threat.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-04
Active exploitation campaign identified
UAT-11587 is confirmed to be exploiting Microsoft 365 services for cyber-espionage activities.
Rescana

More articles in this cluster (3)

Following this threat?

Track Cl-sta-0049, Antino and Outlook in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What organizations are affected?
Government, defense, and policy organizations across Asia and the Middle East are targeted.
What is the primary attack vector?
The campaign uses spear-phishing emails to deliver malicious payloads leveraging Microsoft 365 services.
How can organizations defend against this threat?
Implementing advanced email filtering, monitoring for unusual cloud activity, and user education on phishing are recommended.