# UAT-11587 Deploys Antino Backdoor Against Asian Governments

> China-nexus UAT-11587 is actively targeting government and policy organizations across Asia with the sophisticated Antino backdoor.

- Published: 2026-10-01T03:15:01.000Z
- Severity: high
- Category: Threat Intel
- Tags: China, Espionage, Microsoft 365, UAT 11587, Antino
- Author: Runtime Rebel Intel
- Primary source: https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/
- Canonical: https://runtimerebel.com/blog/uat-11587-deploys-antino-backdoor-against-asian-governments

## Key points

- Government and policy organizations across Asia are at risk from a China-nexus espionage campaign.
- Windows environments within targeted organizations are compromised by the Antino backdoor.
- Implement enhanced spear-phishing defenses and monitor Microsoft 365 Graph API activity.

A China-nexus advanced persistent threat ([APT](/glossary#apt)) group, tracked by Cisco Talos as UAT-11587, has been identified actively targeting government and policy organizations across several Asian countries. This sophisticated campaign leverages spear-[phishing](/glossary#phishing) to deliver a previously undocumented Rust-compiled [backdoor](/glossary#backdoor) named Antino, which utilizes Microsoft 365 services for command and control ([C2](/glossary#c2)). Talos initially observed this activity in September 2025 and, by July 2026, had confirmed at least 16 affected or targeted institutional environments in eight Asian nations, including Taiwan, India, the Philippines, and Cambodia, according to [Cisco Talos](https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/).

## The Antino Backdoor and UAT-11587's Modus Operandi

UAT-11587's operations demonstrate a methodical approach to espionage, focusing on specific targets and employing custom [malware](/glossary#malware). The deployment of the Antino backdoor is a key component of this [threat actor](/glossary#threat-actor)'s toolkit.

### Technical Analysis of Antino

Antino is a custom-developed, Rust-compiled Windows backdoor designed for stealthy [data exfiltration](/glossary#data-exfiltration) and system control. Its capabilities enable a broad range of post-compromise activities, including:

*   **Host [Reconnaissance](/glossary#reconnaissance):** Gathering intelligence about the compromised system and network environment.
*   **Shell and PowerShell Execution:** Executing arbitrary commands to further compromise the system or move laterally.
*   **File Transfer:** Exfiltrating sensitive data and delivering additional payloads.
*   **In-Memory Shellcode Loading:** Executing malicious code directly in memory to evade disk-based detection.
*   **[Persistence](/glossary#persistence):** Establishing a foothold on the compromised system to maintain access over time.

A distinctive feature of Antino is its command-and-control mechanism. It eschews traditional dedicated C2 servers, opting instead to communicate exclusively through Microsoft 365 applications, specifically Outlook and OneDrive, by interacting with the Microsoft Graph [API](/glossary#api). This technique allows the backdoor to blend C2 traffic with legitimate cloud service communications, making it harder to detect and providing a more resilient C2 infrastructure by using legitimate services as 'dead drops'.

### Infection Chain and Delivery Methods

**Prioritizing defenses against China-nexus espionage campaigns** like UAT-11587 requires a clear understanding of their [initial access](/glossary#initial-access) vectors. The campaign typically initiates with highly tailored spear-phishing emails that contain decoy documents. These documents are designed to appear legitimate and relevant to the target's role or organization, often recreating familiar interfaces like Gmail's attachment view. Once a user interacts with the phishing lure, a multi-stage infection chain, typically involving five stages, is triggered. The actor heavily relies on Cloudflare infrastructure for delivery, execution tracking, and [payload](/glossary#payload) staging, leveraging its content delivery network capabilities to obscure their operations. Talos also noted a JavaScript downloader referencing a CloudFront distribution previously associated with the China-nexus group UNC6384, suggesting potential delivery-layer overlap, though Talos assesses this relationship with low confidence.

## [Attribution](/glossary#attribution) and Targeting Profile: UAT-11587

Talos assesses with high confidence that UAT-11587 is a China-nexus actor. This attribution is supported by a confluence of technical and operational indicators, rather than any single data point. Key pieces of evidence include:

*   **Decoy Document Metadata:** Taiwan-focused decoys contained a `zh-CN` language tag, a Simplified Chinese author value, and explicit `+08:00` creation timestamps. While UTC+8 is used in several regions, the combination of these factors is highly consistent with a mainland Chinese environment, where Simplified Chinese is prevalent.
*   **Lure Themes and Victimology:** The lures and observed targets predominantly focus on Taiwanese political, legislative, civil defense, and policy research, alongside regional government, maritime, diplomatic, and security themes. This collection focus aligns with known interests of China-nexus threat actors.
*   **Antino Development Artifacts:** Ten distinct Antino build outputs referenced `rsproxy.cn` in their Cargo registry paths. `rsproxy.cn` is a Rust package mirror intended to improve dependency downloads within mainland China, further indicating a development environment within that region.

The victimology spans public-sector and national-security-adjacent organizations across eight countries. By July 2026, investigations revealed approximately 350 compromised endpoints. Affected sectors include defense, military, national security, executive government, and central government bodies.

Talos also identified overlaps with activity tracked by Symantec as Jewelbug but maintains UAT-11587 as a separate cluster. Symantec noted that Jewelbug conducted both espionage and cryptocurrency fraud, assessing the SEO business supplied access and infrastructure to the espionage, but Talos could not independently verify this connection between the financially motivated activity and the espionage campaign.

## Actionable Recommendations and Mitigations for Antino Backdoor

Defending against a sophisticated actor like UAT-11587, which leverages a custom backdoor and legitimate cloud services, requires a multi-layered security strategy. To effectively detect and mitigate the **Antino backdoor's persistent threat**, organizations should prioritize the following:

*   **Enhanced Email Security:** Implement advanced anti-phishing solutions that can detect highly targeted spear-phishing campaigns, including those impersonating legitimate cloud interfaces.
*   **User Awareness Training:** Conduct regular training for employees on identifying sophisticated phishing attempts and the dangers of interacting with suspicious attachments or links.
*   **Microsoft 365 Monitoring:** Closely monitor Microsoft 365 audit logs and API activity, particularly focusing on unusual or unauthorized interactions with Outlook and OneDrive via Microsoft Graph. Look for atypical access patterns or large data transfers originating from unexpected locations or user accounts.
*   **[Endpoint](/glossary#endpoint) Detection and Response ([EDR](/glossary#edr)):** Deploy and configure EDR solutions to identify anomalous process execution, especially for Rust-compiled binaries, unusual PowerShell activity, and attempts at in-memory shellcode loading.
*   **[Network Segmentation](/glossary#network-segmentation):** Implement network segmentation to limit [lateral movement](/glossary#lateral-movement) potential should an initial compromise occur.
*   **[Threat Hunting](/glossary#threat-hunting):** Actively hunt for indicators of compromise (IoCs) associated with UAT-11587 TTPs, including specific file paths, C2 communication patterns, and unique binary characteristics of the Antino backdoor.

**Related:** [HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2](/blog/hollowgraph-malware-leverages-microsoft-365-calendar-for-stealthy-c2), [US Humanoid Robot Ban: Mitigating Chinese Supply Chain Risks](/blog/us-humanoid-robot-ban-mitigating-chinese-supply-chain-risks)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/uat-11587-deploys-antino-backdoor-against-asian-governments
