VYPR
researchPublished Sep 30, 2026· 1 source

China-Nexus UAT-11587 Targets Asian Governments with Antino Backdoor

A China-linked threat cluster, UAT-11587, has been actively targeting government and policy organizations across Asia since September 2025, deploying a new Rust-compiled backdoor named Antino.

Cisco Talos has identified a China-nexus threat cluster, designated UAT-11587, that has been actively targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia. The campaign, which began in September 2025, deploys a previously undocumented backdoor named 'Antino' by its developers. By July 2026, Talos had observed at least 16 affected or targeted institutional environments across eight Asian countries, with approximately 350 compromised endpoints.

Antino is a sophisticated backdoor compiled in Rust, designed for Windows systems. Its capabilities include host reconnaissance, file transfer, establishing persistence, and executing shellcode in memory. A notable feature of Antino is its command-and-control (C2) mechanism, which exclusively leverages Microsoft 365 services. It communicates through the Microsoft Graph API, utilizing Outlook and OneDrive as dead drops for C2 communications, thereby avoiding the need for conspicuous dedicated servers.

The delivery chain for UAT-11587 typically begins with spear-phishing emails containing tailored decoy documents. These emails lead targets into a multi-stage infection chain, with the actor heavily relying on Cloudflare infrastructure for payload staging and delivery tracking. One recurring delivery branch observed by Talos involved a five-stage infection process, highlighting a methodical and layered approach to compromise.

Talos's assessment of UAT-11587 as China-nexus is based on a convergence of technical and operational indicators. These include decoy document metadata showing a zh-CN language tag and Simplified Chinese author names, along with a +08:00 creation timestamp, suggesting a preparation environment within mainland China. The lure themes and targeting focus on Taiwanese political, legislative, and policy research subjects, alongside broader regional government, maritime, and security interests, align with known China-nexus actor objectives.

Further evidence supporting the attribution comes from Antino's development artifacts. Ten distinct build outputs contained Cargo registry paths referencing 'rsproxy.cn,' a Rust package mirror commonly used within mainland China. While the public accessibility of this service doesn't pinpoint the developer's location, its repeated use indicates reliance on a China-focused infrastructure. Additionally, a JavaScript downloader associated with UAT-11587 referenced a CloudFront distribution previously linked to China-nexus UNC6384 activity, suggesting potential overlap in delivery infrastructure, though this link is assessed with low confidence.

The primary victimology of UAT-11587 consists of public-sector and national-security-adjacent organizations. Sectors affected include defense, military, national security, executive government, and central public administration. The campaign's scope, spanning multiple Asian countries and impacting sensitive government entities, underscores its strategic importance to the threat actor.

While Symantec reported on a related activity set called Jewelbug, which they attributed to the same espionage campaign but also noted financially motivated activity, Talos is tracking UAT-11587 as a separate activity cluster. This distinction is maintained because Talos could not independently verify the connection between the espionage campaign and Jewelbug's financially driven operations, focusing instead on the specific malware and C2 architectures observed in UAT-11587's espionage activities.

Synthesized by Vypr AI