Government and policy organizations across Asia are currently navigating a significant wave of targeted cyber espionage orchestrated by a highly sophisticated, China-nexus threat actor. Identified by Cisco Talos as UAT-11587, this adversary has systematically compromised entities in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. The campaign is notable not only for its geographic breadth but for its utilization of a previously undocumented backdoor known as "Antino," which leverages legitimate cloud infrastructure to mask its malicious communications.
Chronology of the Intrusion Set
The emergence of UAT-11587 can be traced back to September 2025, when researchers first detected a spear-phishing campaign directed at the academic and civil society policy communities in Taiwan. This initial phase demonstrated a high level of preparation, suggesting that the threat actors had conducted extensive reconnaissance to tailor their lures to specific high-value targets.
Following the initial detection in Taiwan, the threat actor significantly expanded its operations. By mid-2026, the campaign had broadened its scope to encompass 16 distinct entities across eight countries. Notably, the activity saw a marked intensification in May 2026, when the group began targeting organizations in Syria, signaling an intent to extend its operational reach beyond the Asian theater. Data from security researchers indicates a concentrated surge in activity between March and June 2026, with a peak occurring on June 8 and 9, 2026, during which dozens of systems within government IT infrastructures were targeted in a coordinated push.

Technical Analysis: The Antino Backdoor
The centerpiece of this operation is the Antino backdoor, a modular, Rust-compiled Windows implant designed for stealth and persistence. Security researcher Ashley Shen of Cisco Talos describes Antino as a versatile tool capable of comprehensive host reconnaissance, shell and PowerShell execution, and arbitrary file transfers.
What distinguishes Antino from more conventional malware is its command-and-control (C2) architecture. Rather than relying on a dedicated, easily identifiable C2 server that could be blocked by network perimeter defenses, the malware utilizes the Microsoft Graph API to interact with legitimate Microsoft 365 services. Specifically, it uses Outlook and OneDrive as dead-drop locations. The malware checks the attacker’s Outlook mailbox every 10 seconds for messages with a specific subject prefix—"commandreq[session_id]"—to receive instructions. This approach effectively blends malicious traffic with legitimate enterprise cloud activity, making it exceptionally difficult for traditional security solutions to flag the communication as suspicious.
Sophisticated Social Engineering Tactics
UAT-11587 has demonstrated a mastery of social engineering, specifically through the use of highly convincing spear-phishing lures. To ensure high delivery rates, the actors have consistently spoofed the identities of trusted entities, successfully bypassing standard email authentication protocols such as SPF and DMARC.
One of the most innovative techniques identified in this campaign involves the replication of the Gmail attachment preview widget. By embedding Base64-encoded MIME parts and styling the email HTML to mimic the native interface of a Google-rendered attachment, the attackers trick users into clicking what appears to be a legitimate file preview. In reality, the link directs the user to a Cloudflare Pages URL, initiating a five-stage infection process that culminates in the deployment of the Antino implant. This level of visual fidelity highlights the adversary’s commitment to bypassing human scrutiny, which remains one of the most effective defensive barriers in modern cybersecurity.

Attribution and Strategic Intent
While establishing absolute attribution in the cyber domain is fraught with difficulty, security experts have classified UAT-11587 as a China-nexus threat with a high degree of confidence. This assessment is supported by several technical and contextual markers, including the presence of Simplified Chinese metadata (zh-CN) in lure documents and the use of the UTC+08:00 time zone in email headers.
Furthermore, the subject matter of the lures—which consistently focuses on maritime disputes, regional security, legislative affairs, and diplomatic relations—aligns perfectly with the geopolitical interests of China-aligned state actors. The campaign’s focus on government IT infrastructure and policy-making bodies in Taiwan and the broader Asia-Pacific region is a classic hallmark of state-sponsored espionage aimed at gathering intelligence on regional policy shifts and security postures.
Although some observers have drawn comparisons between UAT-11587 and previously identified groups like Jewelbug, Earth Alux, and Ink Dragon, Cisco Talos maintains that there is no definitive link between the current espionage campaign and the for-profit, financially motivated activities often attributed to the "hackers-for-hire" cluster known as Jewelbug. This distinction suggests that UAT-11587 is likely an intelligence-gathering unit operating with a strategic, rather than commercial, mandate.
Broader Implications and Defensive Challenges
The success of the UAT-11587 campaign underscores a growing trend in cyber espionage: the "living off the cloud" methodology. By abusing trusted services like Microsoft 365 and leveraging legitimate binaries like "GatherOsState.exe" to facilitate DLL sideloading, the attackers successfully bypass traditional endpoint detection and response (EDR) signatures that look for foreign, unsigned code.

The reliance on the Windows Scripted Diagnostics framework to execute PowerShell commands further complicates incident response. By forcing legitimate Windows components to carry out malicious actions, the threat actor creates a "noisy" environment for defenders, where distinguishing between authorized system administration and malicious exploitation becomes increasingly difficult.
Recommendations for Mitigation
Security agencies and affected organizations are advised to take a multi-layered approach to defense. Given the actor’s reliance on spoofing and visual deception, organizations should prioritize:
- Email Authentication Hardening: Moving beyond basic SPF/DMARC to include robust threat intelligence that analyzes the content and behavior of incoming emails, rather than just the sender’s identity.
- Endpoint Telemetry Monitoring: Implementing strict monitoring of PowerShell execution and the use of system diagnostic tools, which are frequently abused by UAT-11587 to maintain persistence.
- Cloud Service Oversight: Organizations should implement stricter access controls and monitoring for Microsoft 365 API usage, specifically looking for anomalous mailbox activity that could indicate C2 communication.
- User Awareness Training: Employees, particularly those in sensitive policy or research roles, must be trained to recognize the specific visual cues of spoofed widgets and to verify the source of unsolicited documents, even if they appear to originate from known, trusted contacts.
The UAT-11587 campaign serves as a sobering reminder of the persistent and evolving nature of state-aligned cyber operations. As these actors continue to refine their use of legitimate infrastructure to hide in plain sight, the burden of defense shifts toward more proactive, behavioral-based detection strategies. The international community, particularly in the Asia-Pacific region, remains on high alert as investigations into the full extent of this intrusion continue to unfold. The ability of the adversary to adapt its tactics—from targeting academic institutions to infiltrating government infrastructure—suggests that this campaign will remain a significant concern for regional cybersecurity stability for the foreseeable future.
