China-Nexus Threat Actor Targets Asian Governments with Sophisticated Espionage Campaign
A China-nexus threat actor has launched a sophisticated espionage campaign against government and policy organizations in Asia, using a previously undocumented backdoor codenamed Antino. The backdoor, developed in Rust and compiled for Windows, supports host reconnaissance, shell execution, file transfer, and persistence.
The campaign, dubbed UAT-11587 by Cisco Talos, has targeted 16 entities across eight Asian countries, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. The threat actor was first detected in September 2025, spear-phishing against Taiwan's academic, think tank, and civil society policy community.
The Antino backdoor uses Microsoft 365 applications to communicate with its command-and-control (C2) server, utilizing Outlook for command exchange and OneDrive for heartbeat and file transfer. It can list running processes, enumerate directories, run PowerShell scripts, shellcode, or operator-supplied programs using 'cmd.exe'. The threat actor has also spoofed sender identities trusted by the intended recipients to bypass SPF and DMARC security checks.