Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

China‑nexus UAT‑11587 Deploys Antino Backdoor via Spear‑Phishing Against Asian Government and Policy Organizations

Cisco Talos uncovered a China‑linked espionage group (UAT‑11587) delivering the Antino Windows backdoor to government and policy bodies across Asia via spear‑phishing. The campaign uses Microsoft 365 as a stealthy C2 channel, highlighting the need for continuous identity‑and‑access‑control monitoring and cloud‑activity evidence for audit readiness.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 blog.talosintelligence.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
blog.talosintelligence.com

China‑nexus UAT‑11587 Deploys Antino Backdoor via Spear‑Phishing Against Asian Government and Policy Organizations

What Happened — Cisco Talos identified a China‑linked espionage group (UAT‑11587) that has been delivering a custom Rust‑compiled Windows backdoor, dubbed “Antino,” to government and policy institutions across eight Asian countries. The campaign begins with spear‑phishing emails containing decoy documents, then uses a five‑stage infection chain that leverages Microsoft 365 (Outlook and OneDrive) as a stealthy command‑and‑control channel.

Why It Matters for Trust & Control Assurance

  • The attack illustrates how compromised credentials from spear‑phishing can bypass traditional perimeter defenses, underscoring the need for continuous identity‑and‑access‑control monitoring and robust security‑awareness programs.
  • Antino’s use of legitimate Microsoft 365 services as dead‑drops highlights the importance of logging, anomaly detection, and evidence collection on cloud platforms to maintain a defensible audit trail.
  • A control‑assurance program that continuously validates access‑control policies and records cloud‑activity evidence can detect and contain such supply‑chain‑adjacent threats before data exfiltration occurs.

Who Is Affected – Public‑sector agencies, think‑tanks, and policy research organizations in Taiwan, India, the Philippines, Cambodia, and other Asian nations.

Recommended Actions

  • Harden email gateways and enforce MFA for all privileged accounts.
  • Deploy anti‑phishing training and simulated phishing exercises to improve user resilience.
  • Enable comprehensive logging of Microsoft 365 activity (Outlook, OneDrive) and integrate with a SIEM for real‑time anomaly detection.
  • Update incident‑response playbooks to include “cloud‑based dead‑drop” scenarios and conduct tabletop exercises.

Source: Cisco Talos Blog

Technical Notes

  • Antino is a Rust‑compiled Windows backdoor supporting host reconnaissance, PowerShell execution, file transfer, in‑memory shellcode loading, and persistence.
  • C2 traffic is tunneled through Microsoft 365 Graph API, using Outlook messages and OneDrive files as covert channels.
  • Delivery relies on spear‑phishing with tailored decoy documents and Cloudflare infrastructure for staging.

Source: same as above

📰 Original Source
https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →