China-Nexus Threat Actor UAT-11587 Deploys 'Antino' Backdoor Against Asian Governments
A sophisticated China-nexus threat actor, tracked as **UAT-11587** by **Cisco Talos**, has unleashed a previously undocumented Rust-compiled backdoor named **Antino**. This new campaign targets government and policy organizations across several Asian nations, leveraging a complex attack chain and abusing **Microsoft 365** services for command and control.
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor.
The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed **Antino**. **Cisco Talos** is tracking the cluster under the moniker **UAT-11587**.
The threat actor was first detected in September 2025 in connection with a spear-phishing campaign directed against Taiwan's academic, think tank, and civil society policy community. Since then, attacks linked to the intrusion set have expanded to target 16 entities across eight Asian countries.
"**Antino** is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence," security researcher Ashley Shen said. "Its native command-and-control channel operates exclusively through **Microsoft 365**, using **Microsoft Graph** to interact with Outlook and OneDrive."
**UAT-11587** is assessed to share some level of overlap with **Jewelbug**, which, in turn, exhibits tactical similarities with China-aligned clusters known as **CL-STA-0049**, **Earth Alux**, **Ink Dragon**, and **REF7707**. A report published by Broadcom-owned **Symantec** and **Carbon Black** in August 2026 characterized **Jewelbug** as a China-based hackers-for-hire group that carries out espionage operations and a for-profit cryptocurrency fraud business.
However, **Cisco Talos** said its own investigation has failed to unearth a connection between the espionage campaign and **Jewelbug**'s financially motivated activity, prompting it to designate **UAT-11587** as a separate activity set.
## Tracing the China Nexus
The challenges in establishing definitive links notwithstanding, the adversary has been classified as China-nexus with high confidence, citing the presence of zh-CN language and Simplified Chinese metadata in the lure documents and the UTC+08:00 time zone in the spear-phishing message header.
"The campaign's lure theme and targeting provide additional contextual support," **Talos** said. "Its lures and observed targets include Taiwanese political, legislative, civil defense, and policy research subjects, together with regional government, maritime, diplomatic, and security themes. This collection focus is consistent with China-nexus actor interests."
Two other indicators that point to a China-nexus are below:
* Nearly a dozen distinct **Antino** build outputs feature Cargo registry paths referencing rsproxy[.]cn, a high-speed domestic mirror and proxy service for crates.io catering to mainland China.
* A JavaScript downloader associated with **UAT-11587** that references "d32tpl7xt7175h.cloudfront[.]net," a **CloudFront** domain previously flagged by **Arctic Wolf** in connection with a campaign conducted by a China-affiliated threat actor known as **UNC6384** targeting European diplomatic and government entities last year using an unpatched Windows shortcut vulnerability.
Evidence indicates that **UAT-11587** has also trained its sights on organizations in Syria around May 2026, indicating a focus beyond Asia. Attacks mounted by the threat actor have been found to spike between March and early June 2026, with a "concentrated wave" taking place on June 8 and 9, 2026, targeting dozens of systems associated with government IT infrastructure.

## Sophisticated Spear-Phishing Tactics
While the choice of spear-phishing as an initial access vector is unsurprising, the choice of the lures employed suggests the threat actor conducted extensive reconnaissance of the target organizations in order to tailor the content and maximize the chance of success.
In an attempt to lend credibility to the emails, **UAT-11587** is said to have spoofed sender identities trusted by the intended recipients to bypass SPF and DMARC security checks and ensure that the messages land on the victims' inboxes.
"Another social engineering technique used for initial access in this campaign was the closely replicated reconstruction of Gmail's native attachment preview widget inside the email HTML body," Shen explained. "The actor replicated the styling of Gmail's attachment card using four inline PNG images embedded as Base64-encoded MIME parts."
"The entire attachment card was wrapped in an anchor tag pointing to an attacker-controlled [Cloudflare Pages] URL. When a Gmail user opens the email in a browser, Gmail's renderer faithfully displays the attacker-controlled HTML, producing a fake attachment widget that is visually indistinguishable from a legitimate Gmail attachment preview."
An analysis of the lures demonstrates a propensity to target audiences interested in foreign affairs, international security, and government policy, **Talos** added. The attack chain itself is a five-stage process that begins with a HTA or WSF stager and culminates in the deployment of **Antino**.
The **Cloudflare** URL in the phishing email leads to the download of an HTA or WSF file that's then executed to retrieve a JavaScript downloader and decryptor. The next stage triggers a .NET deserialization chain to load "TestAssembly.dll," a .NET downloader and launcher that's responsible for three actions:
* Download and open the lure document to the victim.
* Download a decoy Calculator executable.
* Download and launch the **Antino** backdoor.
The implant ("slc.dll") is launched by means of DLL sideloading using a legitimate **Microsoft**-signed binary ("GatherOsState.exe"). Once launched, the Rust-compiled malware communicates with **Microsoft 365** applications and uses Outlook and OneDrive objects as dead drops, instead of depending on a conspicuous dedicated command-and-control (C2) server.
**Antino** is no different from other backdoors of its kind in that it supports host reconnaissance, command execution, and persistence. It can also list running processes, enumerate directories, run PowerShell scripts, shellcode, operator-supplied programs, and commands using "cmd.exe"
For C2, it uses Outlook for command exchange and OneDrive for heartbeat and file transfer. Specifically, it fetches commands from the threat actor's Outlook mailbox folder every 10 seconds by looking for messages with the subject prefix "command_req_[session_id]."
"The **Antino** backdoor abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components," **Talos** said. "This can complicate behavioral attribution to the original implant, although it does not eliminate observable PowerShell, file-creation, or Registry telemetry."