Cisco Talos says the China-linked cluster UAT-11587 targeted government and policy organizations across Asia and, by July 2026, had touched at least 16 institutional environments in eight countries. The activity includes a previously undocumented Rust Windows backdoor Talos calls Antino.
Antino does not call out to a separate attacker server. It uses Microsoft Graph to hide its commands inside Outlook and OneDrive activity, so its control traffic looks like ordinary Microsoft 365 use unless defenders are inspecting the right account and object changes.
That matters most for organizations that rely on Microsoft 365 for mail and file sharing: the cloud tenant itself becomes part of the attack surface, and network monitoring alone may not expose the command channel. The reporting also leaves one judgment unresolved — how much of the regional activity is one coherent operation versus overlapping access by related actors.
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.