Securityaffairs.Co China-Nexus UAT-11587 Uses Antino Backdoor for Cyber-Espionage
Article Content
- •UAT-11587 targets government and policy organizations in Asia and the Middle East.
- •The Antino backdoor uses Microsoft 365 services for stealthy command-and-control.
- •Advanced techniques like DLL sideloading and social engineering are employed.
A newly identified cyber-espionage campaign attributed to the China-nexus group UAT-11587 is actively exploiting Microsoft 365 services, specifically Outlook and OneDrive, to deploy the Antino backdoor. This sophisticated attack targets government and policy organizations across Asia and the Middle East. The campaign utilizes multi-stage infection chains, including spear-phishing emails that deliver malicious payloads via trusted cloud services. The Antino backdoor, developed in Rust, allows for stealthy command-and-control operations by embedding malicious traffic within legitimate cloud activity. The threat actor employs advanced techniques such as DLL sideloading and social engineering to evade detection. Current mitigation strategies are being discussed to counteract this ongoing threat.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Cl-sta-0049, Antino and Outlook in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What organizations are affected?
What is the primary attack vector?
How can organizations defend against this threat?
Continue Reading
China-Nexus UAT-11587 Campaign Uses Antino Backdoor Across Asia Cisco Talos has identified a cyberespionage campaign, tracked as UAT-11587, linked to a China-nexus threat actor targeting government and policy organizations across eight Asian countries. The campaign, which began in September 2025, has deployed a previously undocumented Rust-compiled backdoor named Antino, utilizing…
Critical RCE Vulnerabilities in GitLab and Dell; Warlock Ransomware Targets SharePoint GitLab and Dell released critical patches for remote code execution vulnerabilities on October 3, 2026. GitLab's AI Gateway vulnerability (CVE-2026-90970) allows arbitrary command execution on self-hosted instances, with a CVSS score of 9.9. Dell's Container Storage Modules have critical flaws (CVSS 10.0) enabling…