Cisco Talos reported a new campaign by a China-nexus threat actor it tracks as UAT-11587, targeting government and policy organisations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand and Myanmar with a previously undocumented backdoor codenamed Antino. First detected in September 2025 in a spear-phishing campaign against Taiwan's academic, think-tank and civil-society policy community, the activity has since expanded to 16 entities across eight Asian countries. Antino is a Rust-compiled Windows backdoor supporting host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence, with a native command-and-control channel that operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive. Talos assessed UAT-11587 as sharing overlap with the China-aligned cluster Jewelbug but treated it as a separate activity set after finding no link to Jewelbug's financially motivated operations. The reliance on legitimate Microsoft 365 services for C2 makes the campaign hard to detect on normal traffic patterns.
| Attribute | Detail |
|---|---|
| Sector | Defence |
| Date | 2026-10-04 |
| Source | The Hacker News |
| Reliability | Tier 2 |