A China-nexus cyber-espionage campaign is targeting government and policy organizations across Asia with a previously undocumented Windows backdoor called Antino. Researchers at Cisco Talos are tracking the threat activity as UAT-11587.
Campaign details
The campaign has targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. By July 2026, Talos had identified at least 16 affected or targeted institutional environments and approximately 350 compromised endpoints.
The campaign's lure theme and targeting provide additional contextual support. Its lures and observed targets include Taiwanese political, legislative, civil defense, and policy research subjects, together with regional government, maritime, diplomatic, and security themes. This collection focus is consistent with China-nexus actor interests,” Talos said.
The most notable feature of Antino is its use of legitimate Microsoft 365 services as command-and-control (C2) infrastructure. Instead of relying on a traditional attacker-controlled server, the malware communicates through Microsoft Outlook and OneDrive using Microsoft Graph.
About Antino
Antino is a Rust-compiled Windows backdoor capable of gathering information about infected systems, executing commands through Windows shell and PowerShell, transferring files, loading shellcode directly into memory and maintaining persistence.
About the infection
The infection generally begins with a carefully prepared spear-phishing email. Attackers used government, diplomatic, maritime, legislative and foreign-policy themes designed to appear relevant to their intended victims.
Attack tactic
In some cases, the attackers recreated Gmail’s attachment-preview interface inside the email. When victims interacted with the fake attachment, they were directed to attacker-controlled infrastructure.
The attack then proceeds through multiple stages involving HTA or WSF files, JavaScript and a .NET-based downloader before ultimately installing Antino. The malware has also been deployed through DLL sideloading, using a legitimate Microsoft-signed executable to load the malicious DLL.
Once installed, Antino uses Microsoft Graph to communicate with Microsoft 365. Outlook is used for receiving commands, while OneDrive handles heartbeat communications and file transfers. This allows malicious traffic to terminate at legitimate Microsoft infrastructure, potentially making conventional network-based detection more difficult.
Impact on systems
A successful Antino infection can provide attackers with persistent access to a Windows system, allowing them to conduct reconnaissance, execute commands, run PowerShell, access files and transfer data.
The targeting of government agencies, diplomatic organizations, universities, think tanks and policy groups suggests that the campaign is focused primarily on intelligence gathering and espionage rather than ordinary financial cybercrime.
Cisco Talos assessed UAT-11587 as China-nexus with high confidence, citing technical, language, infrastructure and targeting indicators. However, researchers noted that attribution to a specific Chinese group remains more complicated.
Read the original article:
