ConciseSignal
Following

Cisco Talos uncovers China-linked Antino backdoor campaign

Cisco Talos has identified a Chinese-linked threat group, UAT-11587, targeting government and policy organizations in at least eight Asian countries with a new Rust-based Windows backdoor called Antino. The campaign, observed since late 2025, used spear-phishing and a complex multi-stage infection chain, with Antino communicating exclusively via Microsoft 365 services. The group leveraged Cloudflare infrastructure for delivery and cover, with confirmed targets including institutions in Taiwan, India, and the Philippines.

Why it mattersThe discovery highlights China-based cyber-espionage targeting government and policy entities across Asia, using advanced tactics to evade traditional detection. The use of common cloud platforms for command and control complicates threat mitigation for organizations.

Sources covering this

Cisco TalosPrimaryChina-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor10:00 AM →

In this story

Concise Signal DailyEnterprise AI, security & business tech.Weekdays, 7am Eastern · Sample issue

More in Cybersecurity