
China-Nexus UAT-11587 Deploys 'Antino' Backdoor in Targeted Asian Espionage Campaign
A China-linked threat actor, UAT-11587, is actively targeting government and policy organizations across Asia using a novel backdoor called Antino. The campaign leverages legitimate cloud services like Outlook and OneDrive for command-and-control communications.
Encrygma is selling the entire Full Cyber Weapon Research of China-Nexus UAT-11587 Deploys 'Antino' Backdoor in Targeted Asian Espionage Campaign for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- Asia-Pacific
- Confidence:
- High Confidence
- Source:
- Cisco Talos
- Read Time:
- 4 min
Executive Summary
In early October 2026, security researchers identified a sophisticated cyber espionage campaign targeting government, academic, and civil society policy organizations across Asia. The campaign, orchestrated by a China-nexus threat actor tracked as UAT-11587, utilizes a previously undocumented backdoor dubbed 'Antino'. This operation highlights the continued evolution of state-sponsored actors in leveraging legitimate enterprise cloud infrastructure to mask malicious command-and-control (C2) traffic.
Threat Analysis
UAT-11587 has demonstrated a high degree of operational security, focusing its efforts on sensitive policy-making entities in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. The group's primary objective appears to be long-term intelligence gathering and data exfiltration. By embedding their C2 infrastructure within trusted platforms like Microsoft Outlook and OneDrive, the attackers effectively bypass traditional network-based detection mechanisms that rely on domain reputation or traffic volume analysis.
Technical Details
The Antino backdoor is a modular, lightweight implant designed for stealth. Upon initial infection—typically delivered via highly targeted spear-phishing emails—the malware establishes persistence on the host system. Its most notable feature is the use of the Microsoft Graph API to interact with compromised or attacker-controlled Outlook and OneDrive accounts. By utilizing these legitimate services, the malware blends in with standard corporate traffic, making it exceptionally difficult for security operations centers (SOCs) to identify the malicious activity without deep endpoint visibility and behavioral analysis.
Attribution Assessment
Based on the TTPs (Tactics, Techniques, and Procedures) and the geographic focus on policy organizations in the Indo-Pacific region, Cisco Talos and other intelligence partners have attributed this activity to a China-nexus threat actor. The group's methodology aligns with broader trends observed in recent years, where state-sponsored actors have shifted toward 'living-off-the-cloud' techniques to maintain persistent access while minimizing their digital footprint.
Implications
The use of Antino represents a significant challenge for regional security. As these actors continue to refine their ability to exploit trusted cloud services, organizations must move beyond perimeter-based defenses. The potential for long-term, undetected espionage against critical policy-making bodies poses a severe risk to regional stability and diplomatic integrity.
Recommendations
- Implement strict conditional access policies for cloud services, limiting access to known-good IP ranges and managed devices.
- Deploy advanced Endpoint Detection and Response (EDR) solutions capable of monitoring API-level interactions with cloud services.
- Conduct regular threat hunting exercises focused on identifying anomalous patterns in Microsoft 365 logs, specifically looking for unusual Graph API usage.
- Enhance user awareness training regarding spear-phishing, specifically focusing on documents that appear to originate from trusted policy or academic partners.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Iranian-Linked 'Nimbus Manticore' Expands Espionage Arsenal with Advanced Backdoors

Iranian 'Nimbus Manticore' APT Escalates Global Espionage via Sophisticated Coding Test Phishing

