China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos attributes China-nexus UAT-11587 to espionage against Asian governments using the Rust-based Antino backdoor, with ~350 compromised endpoints in eight countries.
Cisco Talos tracks UAT-11587, a China-nexus espionage actor first observed in September 2025, targeting government and policy organizations across Asia including Taiwan, India, the Philippines, and Cambodia. The actor delivers a previously undocumented Rust-compiled Windows backdoor called Antino, which supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading, and persistence. Antino's C2 operates exclusively through Microsoft Graph, using Outlook and OneDrive objects as dead drops instead of a dedicated command server. By July 2026, Talos identified at least 16 affected or targeted institutional environments across eight countries, totaling approximately 350 compromised endpoints, with delivery via spear-phishing, tailored decoy documents, a five-stage infection chain, and heavy Cloudflare infrastructure use. Talos found partial overlap with Symantec's Jewelbug reporting but tracks UAT-11587 as a separate cluster.