WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

Low-angle view of tall server racks in a dim data hallAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

Talos identified a recurring delivery branch that began with spear-phishing (messages that impersonate someone to obtain passwords or money) emails and tailored decoy documents, followed by a five-stage infection chain. Talos first observed UAT-11587 activity in September 2025.

Antino is a Rust-compiled Windows backdoor that provides support for host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence. Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.

The actor relied heavily on Cloudflare infrastructure for delivery, execution tracking, and payload staging. Based on the development, preparation-environment, and targeting indicators detailed in this report, Talos assesses with high confidence that UAT-11587 is China-nexus.

Sources & evidence