Cisco Talos has pulled back the curtain on a long-running espionage push against Asian governments, and the most interesting part is not how the intruders get in. It is where they hide afterward.
The group, tracked as UAT-11587, has been active since at least September 2025 and has hit 16 government and policy organizations across eight countries, among them Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. Talos assesses with high confidence that the cluster is China-nexus.
Its signature tool is Antino, a previously undocumented backdoor written in Rust for 32-bit and 64-bit Windows. Rather than phone home to a dedicated command server, Antino talks through Microsoft Graph, reading tasking from an Outlook mailbox and dropping stolen files into OneDrive. That makes its traffic look like ordinary Microsoft 365 activity.
The implant checks the mailbox roughly every ten seconds, looking for subjects prefixed command_req_[session_id]. It answers under command_res_[session_id]. It supports shell and PowerShell execution, reconnaissance, file transfer, in-memory shellcode, and persistence.
Access starts with tailored spear-phishing. One lure reproduced a real Taiwan Ministry of Finance ruling; another reused an Associated Press story. The intruders spoofed trusted senders so SPF passed while DMARC failed, and because the impersonated domain only monitored rather than rejected, the mail still landed. A fake Gmail attachment card, rebuilt from inline images and pointed at a Cloudflare Pages URL, carried the click.
A five-stage chain follows, ending with the backdoor sideloaded through a signed Microsoft diagnostic binary. Talos counted roughly 350 compromised endpoints, including a burst of about 57 in India over two days in June.
