
China-Nexus 'Antino' Backdoor Campaign Targets Asian Government Policy Networks via Cloud Infrastructure
A sophisticated China-aligned threat actor, tracked as UAT-11587, is deploying the novel 'Antino' backdoor to infiltrate government and policy organizations across Asia. The campaign leverages legitimate Outlook and OneDrive services for command-and-control, complicating detection efforts.
Encrygma is selling the entire Full Cyber Weapon Research of China-Nexus 'Antino' Backdoor Campaign Targets Asian Government Policy Networks via Cloud Infrastructure for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- Asia-Pacific
- Confidence:
- High Confidence
- Source:
- Cisco Talos
- Read Time:
- 4 min
Executive Summary
In early October 2026, security researchers identified a persistent cyber-espionage campaign targeting government and policy-oriented organizations across South and Southeast Asia. The campaign, attributed to a China-nexus threat actor designated as UAT-11587, utilizes a previously undocumented modular backdoor dubbed 'Antino'. This operation represents a shift toward abusing trusted cloud-based productivity suites to facilitate long-term intelligence gathering.
Threat Analysis
UAT-11587 has demonstrated a high degree of operational security, focusing on high-value targets in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. The group’s primary objective appears to be the exfiltration of sensitive policy documents and strategic communications. By embedding their command-and-control (C2) infrastructure within Microsoft Outlook and OneDrive, the attackers effectively blend malicious traffic with legitimate enterprise activity, bypassing traditional network-based anomaly detection.
Technical Details
The Antino backdoor is a lightweight, modular implant designed for stealth. Upon initial compromise—typically achieved via highly tailored spear-phishing lures—the malware establishes persistence by masquerading as a legitimate system process. The C2 mechanism is particularly notable: rather than connecting to a dedicated malicious server, the implant polls specific Outlook folders or OneDrive directories for encrypted tasking files. This 'living-off-the-cloud' approach allows the actor to maintain communication channels that are often whitelisted by corporate security policies.
Attribution Assessment
Based on the targeting profile, the use of specific TTPs (Tactics, Techniques, and Procedures) consistent with regional intelligence requirements, and the infrastructure overlap with previous campaigns, researchers have assessed with high confidence that this activity is state-sponsored. The focus on policy communities in Taiwan and India aligns with broader geopolitical objectives observed in other China-aligned clusters, such as Earth Baxia and SHADOW-EARTH-067, which have also increasingly weaponized cloud platforms throughout 2026.
Implications
The reliance on cloud-native C2 infrastructure poses a significant challenge for defenders. Traditional perimeter defenses are largely ineffective against this class of threat, as the traffic originates from trusted, reputable service providers. Organizations in the affected regions must shift their focus toward endpoint detection and response (EDR) and behavioral analysis of user-account activity to identify the subtle signs of unauthorized access to cloud storage.
Recommendations
- Implement strict conditional access policies for cloud services, limiting access to known-good IP ranges and managed devices.
- Deploy advanced EDR solutions capable of monitoring process injection and suspicious API calls associated with cloud-syncing applications.
- Conduct regular threat hunting exercises specifically looking for anomalous file creation or synchronization patterns within OneDrive and Outlook environments.
- Enhance user awareness training regarding spear-phishing lures that mimic policy-related communications or academic invitations.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

China-Nexus UAT-11587 Deploys 'Antino' Backdoor via Microsoft 365 Infrastructure

China-Aligned TA419 Targets U.S. AI Policy Experts via Sophisticated AiTM Phishing Campaign

