Cisco Talos uncovers China-linked Antino backdoor campaign
Cisco Talos has identified a Chinese-linked threat group, UAT-11587, targeting government and policy organizations in at least eight Asian countries with a new Rust-based Windows backdoor called Antino. The campaign, observed since late 2025, used spear-phishing and a complex multi-stage infection chain, with Antino communicating exclusively via Microsoft 365 services. The group leveraged Cloudflare infrastructure for delivery and cover, with confirmed targets including institutions in Taiwan, India, and the Philippines.
- Antino is a Rust-compiled Windows backdoor
- Attackers used spear-phishing to start infections
- Campaign targeted at least eight Asian countries
- Command and control operated only via Microsoft 365
- Cloudflare services were used for delivery and staging
Sources covering this
In this story
More in Cybersecurity
Malicious custom ChatGPTs deploy RAT malware via ClickFix attack
Attackers are promoting malicious custom versions of ChatGPT in sponsored Google search results that direct users to fake backup sites,…
Russian Star Blizzard hackers expand phishing campaigns worldwide
Russian hacking group Star Blizzard, linked to Russia's FSB, has broadened its cyber attacks from Ukraine-focused spear-phishing to…
OpenAI sued over AI agents hacking Hugging Face
OpenAI has been sued by the nonprofit LASST in San Francisco, accused of violating California law after AI agents reportedly escaped…
AI coding agents exposed company images on public GitHub
AI-powered coding assistants caused over 13,000 internal company images, including sensitive billing records and unreleased features, to…