Chinese State-Backed Hackers Target AI Firms, Asian Governments with Sophisticated Phishing and Backdoors
New reports from cybersecurity firms **Proofpoint** and **Cisco Talos** detail recent campaigns by Chinese government-backed threat actors. These groups are leveraging sophisticated social engineering tactics, impersonating prominent figures to target AI experts, and deploying custom backdoors like **Antino** against government organizations across Asia for intelligence gathering.
Chinese government-backed hacking groups have allegedly intensified their activities, focusing on artificial intelligence companies and several Asian governments in recent campaigns, according to two new reports this week.
### AI Experts Targeted with Impersonation Tactics
On Thursday, researchers at **Proofpoint** highlighted an incident from July where a Chinese threat actor, identified as **TA419**, conducted multiple phishing attacks. These attacks involved impersonating prominent economists and even a former member of the White House Office of Science and Technology Policy leadership team.
The emails specifically targeted AI experts affiliated with universities, think tanks, and law firms. Initial communications, sent on July 8, impersonated former White House official **Lynne Edwards Parker** before switching to prominent foreign policy expert **Heidi Crebo-Rediker**.
The lure offered recipients the opportunity to join a fictitious "AI Policy Advisory Committee" or participate in a fake Senate report on AI export controls. **Proofpoint** researchers noted, "The group first sent benign conversation starter emails, which included calls to action themed around AI policy such as joining an βAI Policy Advisory Committee,β to build rapport and solicit a response from the target.β
Upon receiving a response, the hackers deployed a URL redirection chain designed to steal credentials. The malicious links led to a **OneDrive** credential phishing page, prompting victims to provide their login information.
**Proofpoint** further indicated that **TA419** has a history of targeting individuals within U.S. and Japanese think tanks, defense contractors, and universities. The group typically registers domains impersonating legitimate organizations such as **The Heritage Foundation**, the **Japan-Taiwan Exchange Association**, and the office of Japanβs Defense Minister.
### Antino Backdoor Deployed Across Asia
The **Proofpoint** report followed an advisory from **Cisco Talos**, published a day earlier, detailing a new backdoor named **Antino**. This backdoor is being used by Chinese state-backed groups to target government organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria.
**Cisco** incident responders identified 16 affected or targeted organizations across eight Asian countries between September 2025 and July 2026. The **Antino** backdoor facilitates reconnaissance, file transfers, and persistent access to victim systems, with the overarching goal of intelligence gathering.
Most victims were initially subjected to phishing emails and decoy documents, designed to entice them into responding, clicking on links, or downloading malicious files. **Cisco** stated, "Talos first identified [the groupβs] campaign while investigating a spear-phishing campaign directed at Taiwan's academic, think tank, and civil society policy community in March 2026."
Further investigation revealed that the activity extended beyond the initial Taiwan operation. **Cisco Talos** subsequently identified confirmed or probable affected government and security environments across multiple Asian countries, alongside additional regional targeting supported by lure content.
The campaign commenced in the Philippines and continued through to a recent wave in June, which targeted organizations in India. In total, **Cisco** found approximately 350 compromised endpoints across the eight countries.
The hackers utilized a variety of lures, including spoofed news reports about the Trump administration, invitations mimicking real events, and legislative documents.
**Cisco Talos** also found overlaps with another campaign identified by researchers at **Symantec**, which similarly observed Chinese state hackers employing the **Antino** backdoor.