News Room
16
Share
China-Nexus UAT-11587 Deploys 'Antino' Backdoor in Targeted Asian Espionage Campaign
highCyber Espionage

China-Nexus UAT-11587 Deploys 'Antino' Backdoor in Targeted Asian Espionage Campaign

A China-linked threat actor, UAT-11587, is actively targeting government and policy organizations across Asia using a novel backdoor called Antino. The campaign leverages legitimate cloud services like Outlook and OneDrive for command-and-control communications.

₿

Encrygma is selling the entire Full Cyber Weapon Research of China-Nexus UAT-11587 Deploys 'Antino' Backdoor in Targeted Asian Espionage Campaign for ₿ 0.10 BTC. Contact us.

05 October 2026Last updated 05 October 20264 min readCisco Talos
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
High
Actor Type:
Nation-State
Geography:
Asia-Pacific
Confidence:
High Confidence
Source:
Cisco Talos
Read Time:
4 min

Executive Summary

In early October 2026, security researchers identified a sophisticated cyber espionage campaign targeting government, academic, and civil society policy organizations across Asia. The campaign, orchestrated by a China-nexus threat actor tracked as UAT-11587, utilizes a previously undocumented backdoor dubbed 'Antino'. This operation highlights the continued evolution of state-sponsored actors in leveraging legitimate enterprise cloud infrastructure to mask malicious command-and-control (C2) traffic.

Threat Analysis

UAT-11587 has demonstrated a high degree of operational security, focusing its efforts on sensitive policy-making entities in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. The group's primary objective appears to be long-term intelligence gathering and data exfiltration. By embedding their C2 infrastructure within trusted platforms like Microsoft Outlook and OneDrive, the attackers effectively bypass traditional network-based detection mechanisms that rely on domain reputation or traffic volume analysis.

Technical Details

The Antino backdoor is a modular, lightweight implant designed for stealth. Upon initial infection—typically delivered via highly targeted spear-phishing emails—the malware establishes persistence on the host system. Its most notable feature is the use of the Microsoft Graph API to interact with compromised or attacker-controlled Outlook and OneDrive accounts. By utilizing these legitimate services, the malware blends in with standard corporate traffic, making it exceptionally difficult for security operations centers (SOCs) to identify the malicious activity without deep endpoint visibility and behavioral analysis.

Attribution Assessment

Based on the TTPs (Tactics, Techniques, and Procedures) and the geographic focus on policy organizations in the Indo-Pacific region, Cisco Talos and other intelligence partners have attributed this activity to a China-nexus threat actor. The group's methodology aligns with broader trends observed in recent years, where state-sponsored actors have shifted toward 'living-off-the-cloud' techniques to maintain persistent access while minimizing their digital footprint.

Implications

The use of Antino represents a significant challenge for regional security. As these actors continue to refine their ability to exploit trusted cloud services, organizations must move beyond perimeter-based defenses. The potential for long-term, undetected espionage against critical policy-making bodies poses a severe risk to regional stability and diplomatic integrity.

Recommendations

  1. Implement strict conditional access policies for cloud services, limiting access to known-good IP ranges and managed devices.
  2. Deploy advanced Endpoint Detection and Response (EDR) solutions capable of monitoring API-level interactions with cloud services.
  3. Conduct regular threat hunting exercises focused on identifying anomalous patterns in Microsoft 365 logs, specifically looking for unusual Graph API usage.
  4. Enhance user awareness training regarding spear-phishing, specifically focusing on documents that appear to originate from trusted policy or academic partners.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo