News Room
16
Share
China-Nexus 'Antino' Backdoor Campaign Targets Asian Government Policy Networks via Cloud Infrastructure
highCyber Espionage

China-Nexus 'Antino' Backdoor Campaign Targets Asian Government Policy Networks via Cloud Infrastructure

A sophisticated China-aligned threat actor, tracked as UAT-11587, is deploying the novel 'Antino' backdoor to infiltrate government and policy organizations across Asia. The campaign leverages legitimate Outlook and OneDrive services for command-and-control, complicating detection efforts.

₿

Encrygma is selling the entire Full Cyber Weapon Research of China-Nexus 'Antino' Backdoor Campaign Targets Asian Government Policy Networks via Cloud Infrastructure for ₿ 0.10 BTC. Contact us.

09 October 2026Last updated 09 October 20264 min readCisco Talos
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
High
Actor Type:
Nation-State
Geography:
Asia-Pacific
Confidence:
High Confidence
Source:
Cisco Talos
Read Time:
4 min

Executive Summary

In early October 2026, security researchers identified a persistent cyber-espionage campaign targeting government and policy-oriented organizations across South and Southeast Asia. The campaign, attributed to a China-nexus threat actor designated as UAT-11587, utilizes a previously undocumented modular backdoor dubbed 'Antino'. This operation represents a shift toward abusing trusted cloud-based productivity suites to facilitate long-term intelligence gathering.

Threat Analysis

UAT-11587 has demonstrated a high degree of operational security, focusing on high-value targets in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. The group’s primary objective appears to be the exfiltration of sensitive policy documents and strategic communications. By embedding their command-and-control (C2) infrastructure within Microsoft Outlook and OneDrive, the attackers effectively blend malicious traffic with legitimate enterprise activity, bypassing traditional network-based anomaly detection.

Technical Details

The Antino backdoor is a lightweight, modular implant designed for stealth. Upon initial compromise—typically achieved via highly tailored spear-phishing lures—the malware establishes persistence by masquerading as a legitimate system process. The C2 mechanism is particularly notable: rather than connecting to a dedicated malicious server, the implant polls specific Outlook folders or OneDrive directories for encrypted tasking files. This 'living-off-the-cloud' approach allows the actor to maintain communication channels that are often whitelisted by corporate security policies.

Attribution Assessment

Based on the targeting profile, the use of specific TTPs (Tactics, Techniques, and Procedures) consistent with regional intelligence requirements, and the infrastructure overlap with previous campaigns, researchers have assessed with high confidence that this activity is state-sponsored. The focus on policy communities in Taiwan and India aligns with broader geopolitical objectives observed in other China-aligned clusters, such as Earth Baxia and SHADOW-EARTH-067, which have also increasingly weaponized cloud platforms throughout 2026.

Implications

The reliance on cloud-native C2 infrastructure poses a significant challenge for defenders. Traditional perimeter defenses are largely ineffective against this class of threat, as the traffic originates from trusted, reputable service providers. Organizations in the affected regions must shift their focus toward endpoint detection and response (EDR) and behavioral analysis of user-account activity to identify the subtle signs of unauthorized access to cloud storage.

Recommendations

  1. Implement strict conditional access policies for cloud services, limiting access to known-good IP ranges and managed devices.
  2. Deploy advanced EDR solutions capable of monitoring process injection and suspicious API calls associated with cloud-syncing applications.
  3. Conduct regular threat hunting exercises specifically looking for anomalous file creation or synchronization patterns within OneDrive and Outlook environments.
  4. Enhance user awareness training regarding spear-phishing lures that mimic policy-related communications or academic invitations.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo