Asia-Wide Government Hack Targets Intelligence Gathering
Cisco Talos uncovered a cluster of activity known as UAT-11587 targeting government and policy organizations across Asia. The campaign, which began in September 2025, delivered a previously undocumented backdoor referred to as 'Antino' in developer artifacts. By July 2026, at least 16 affected or targeted institutional environments were identified across eight Asian countries.
The Antino backdoor is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading, and persistence. It operates exclusively through Microsoft 365 using Microsoft Graph to interact with Outlook and OneDrive. A recurring delivery branch used spear-phishing emails and tailored decoy documents followed by a five-stage infection chain.
Talos assessed with high confidence that UAT-11587 is China-nexus based on technical and operational evidence, including decoy document metadata, lure theme, and targeting. The campaign's focus on Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria suggests a sustained targeting of government and national security-adjacent organizations for intelligence gathering.