
China-Nexus 'Antino' Backdoor Targets Asian Government Networks via Cloud Infrastructure
A sophisticated China-nexus threat actor, tracked as UAT-11587, is deploying the newly discovered 'Antino' backdoor to infiltrate government and policy organizations across Asia. The campaign leverages legitimate cloud services for command-and-control, complicating detection efforts.
Encrygma is selling the entire Full Cyber Weapon Research of China-Nexus 'Antino' Backdoor Targets Asian Government Networks via Cloud Infrastructure for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- Asia-Pacific
- Confidence:
- High Confidence
- Source:
- Cisco Talos
- Read Time:
- 4 min
Executive Summary
Recent intelligence reports from Cisco Talos have identified a persistent cyber espionage campaign targeting government and policy-oriented organizations across Asia. The campaign, orchestrated by a China-nexus threat actor designated as UAT-11587, utilizes a previously undocumented backdoor named 'Antino'. This operation has been observed targeting entities in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, signaling a broad strategic interest in regional policy and geopolitical intelligence.
Threat Analysis
UAT-11587 has demonstrated a high level of operational security, focusing on long-term persistence within target networks. The group's methodology involves highly targeted spear-phishing campaigns that serve as the initial access vector. Once a foothold is established, the actors deploy the Antino backdoor, which is specifically designed to evade traditional signature-based detection by blending into legitimate network traffic.
Technical Details
The Antino backdoor is notable for its innovative use of legitimate cloud infrastructure for command-and-control (C2) communications. Specifically, the malware leverages Microsoft Outlook and OneDrive APIs to exfiltrate data and receive instructions. By routing malicious traffic through these trusted services, the threat actor effectively bypasses perimeter security controls that might otherwise flag unauthorized outbound connections. The modular nature of the backdoor allows the attackers to deploy additional payloads, including credential harvesters and lateral movement tools, once the initial environment is compromised.
Attribution Assessment
Based on the targeting profile, infrastructure reuse, and TTPs (Tactics, Techniques, and Procedures), the activity is assessed with high confidence to be linked to China-nexus espionage operations. The focus on academic, think tank, and civil society policy communities in Taiwan and Southeast Asia aligns with historical patterns of state-sponsored intelligence gathering aimed at influencing regional policy and monitoring geopolitical shifts.
Implications
The use of cloud-native C2 channels represents a significant challenge for defenders. As organizations increasingly rely on SaaS platforms like Microsoft 365, the line between legitimate administrative activity and malicious exfiltration becomes blurred. This campaign underscores the necessity for advanced behavioral analytics that can distinguish between normal user behavior and automated, malicious API interactions.
Recommendations
Organizations in the affected regions should prioritize the following: 1) Implement strict conditional access policies for cloud applications to limit API-based access. 2) Monitor for anomalous API calls originating from internal endpoints to Microsoft 365 services. 3) Enhance email security filtering to detect sophisticated spear-phishing attempts. 4) Conduct regular threat hunting exercises focused on identifying unauthorized persistence mechanisms within cloud-integrated environments.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



