News Room
16
Share
China-Nexus 'Antino' Backdoor Targets Asian Government Networks via Cloud Infrastructure
highCyber Espionage

China-Nexus 'Antino' Backdoor Targets Asian Government Networks via Cloud Infrastructure

A sophisticated China-nexus threat actor, tracked as UAT-11587, is deploying the newly discovered 'Antino' backdoor to infiltrate government and policy organizations across Asia. The campaign leverages legitimate cloud services for command-and-control, complicating detection efforts.

₿

Encrygma is selling the entire Full Cyber Weapon Research of China-Nexus 'Antino' Backdoor Targets Asian Government Networks via Cloud Infrastructure for ₿ 0.10 BTC. Contact us.

06 October 2026Last updated 06 October 20264 min readCisco Talos
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
High
Actor Type:
Nation-State
Geography:
Asia-Pacific
Confidence:
High Confidence
Source:
Cisco Talos
Read Time:
4 min

Executive Summary

Recent intelligence reports from Cisco Talos have identified a persistent cyber espionage campaign targeting government and policy-oriented organizations across Asia. The campaign, orchestrated by a China-nexus threat actor designated as UAT-11587, utilizes a previously undocumented backdoor named 'Antino'. This operation has been observed targeting entities in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, signaling a broad strategic interest in regional policy and geopolitical intelligence.

Threat Analysis

UAT-11587 has demonstrated a high level of operational security, focusing on long-term persistence within target networks. The group's methodology involves highly targeted spear-phishing campaigns that serve as the initial access vector. Once a foothold is established, the actors deploy the Antino backdoor, which is specifically designed to evade traditional signature-based detection by blending into legitimate network traffic.

Technical Details

The Antino backdoor is notable for its innovative use of legitimate cloud infrastructure for command-and-control (C2) communications. Specifically, the malware leverages Microsoft Outlook and OneDrive APIs to exfiltrate data and receive instructions. By routing malicious traffic through these trusted services, the threat actor effectively bypasses perimeter security controls that might otherwise flag unauthorized outbound connections. The modular nature of the backdoor allows the attackers to deploy additional payloads, including credential harvesters and lateral movement tools, once the initial environment is compromised.

Attribution Assessment

Based on the targeting profile, infrastructure reuse, and TTPs (Tactics, Techniques, and Procedures), the activity is assessed with high confidence to be linked to China-nexus espionage operations. The focus on academic, think tank, and civil society policy communities in Taiwan and Southeast Asia aligns with historical patterns of state-sponsored intelligence gathering aimed at influencing regional policy and monitoring geopolitical shifts.

Implications

The use of cloud-native C2 channels represents a significant challenge for defenders. As organizations increasingly rely on SaaS platforms like Microsoft 365, the line between legitimate administrative activity and malicious exfiltration becomes blurred. This campaign underscores the necessity for advanced behavioral analytics that can distinguish between normal user behavior and automated, malicious API interactions.

Recommendations

Organizations in the affected regions should prioritize the following: 1) Implement strict conditional access policies for cloud applications to limit API-based access. 2) Monitor for anomalous API calls originating from internal endpoints to Microsoft 365 services. 3) Enhance email security filtering to detect sophisticated spear-phishing attempts. 4) Conduct regular threat hunting exercises focused on identifying unauthorized persistence mechanisms within cloud-integrated environments.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo