China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
What happened
Talos identified a recurring delivery branch that began with spear-phishing (messages that impersonate someone to obtain passwords or money) emails and tailored decoy documents, followed by a five-stage infection chain. Talos first observed UAT-11587 activity in September 2025.
Antino is a Rust-compiled Windows backdoor that provides support for host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence. Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.
The actor relied heavily on Cloudflare infrastructure for delivery, execution tracking, and payload staging. Based on the development, preparation-environment, and targeting indicators detailed in this report, Talos assesses with high confidence that UAT-11587 is China-nexus.
Sources & evidence
- Cisco Talos Primary / official
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor ↗
https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/