Skip to content
Sunday, 4 October 2026
Tenesys AI News
Subscribe
Cyber Security· Important

Cisco Talos exposes China-nexus group UAT-11587 using new 'Antino' backdoor against Asian governments

In short: Cisco Talos disclosed a China-nexus threat cluster, tracked as UAT-11587, that has targeted government, defense, diplomatic and policy organizations across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria since September 2025. The group delivers a previously undocumented Rust-compiled Windows backdoor called Antino via spear-phishing with spoofed senders and fake Gmail attachment widgets. Antino communicates covertly through Microsoft 365 (Outlook/OneDrive via Microsoft Graph) instead of a traditional C2 server, and the group heavily relies on Cloudflare infrastructure for delivery and staging. Talos found roughly 350 compromised endpoints across eight countries, with the largest wave hitting around 57 Indian endpoints in a single two-day period.

Source: Cisco TalosCisco TalosOriginal article ↗

This summary was generated automatically by AI from Cisco Talos's publication. It is our own text, not a copy of the original — facts, figures and quotes belong to the source, linked above and below.

What changed?

  • 1New Rust-compiled Windows backdoor 'Antino' supporting recon, shell/PowerShell execution, file transfer, in-memory shellcode loading and persistence
  • 2C2 channel runs exclusively through Microsoft 365 (Outlook and OneDrive objects via Microsoft Graph) instead of a dedicated server
  • 3Spear-phishing uses SMTP/From header mismatch (SPF pass, DMARC fail due to p=none policy) to spoof trusted senders
  • 4Attackers clone Gmail's native attachment preview widget using Base64-embedded PNGs linking to Cloudflare Pages URLs
  • 5Campaign active September 2025–July 2026; at least 10 confirmed and 5 probable affected environments plus ~350 compromised endpoints across 8 countries
  • 6Targets include defense, foreign affairs, justice/law enforcement, legislatures, e-government services, think tanks and civil-society organizations

Why it matters

This shows a nation-state actor abusing trusted cloud services (Microsoft 365, Cloudflare) as covert infrastructure, making detection harder for traditional network monitoring, and using email authentication gaps (SPF/DMARC misalignment) and convincing UI-spoofing to bypass user suspicion.

What it means for AI agents and contact centers

If your organization operates in government, policy, diplomatic or civil-society sectors in Asia, or interacts with such clients, review email authentication enforcement (move DMARC policies from p=none toward quarantine/reject), monitor for anomalous Microsoft Graph API activity involving Outlook/OneDrive, and train staff to recognize spoofed Gmail attachment widgets and sender-domain mismatches in phishing emails.

Sources

  • Cisco TalosOfficialPrimary source
    „China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor“
    30 Sept 2026, 13:00
    Original article →
Published by source
30 Sept 2026, 13:00
Found by our system
2 Oct 2026, 22:23
Summary generated
3 Oct 2026, 20:01

This article was written by AI from the original source. Facts, numbers and prices come from the source; missing values are marked “Not specified”. Legal notice, copyright and privacy