China-linked hackers target Asian governments with Antino
Cisco Talos says UAT-11587 hit at least 16 government and policy groups in eight Asian countries with a Rust backdoor run through Microsoft 365.
By Lena Hart · Published · Updated · 4 min read

Cisco Talos has uncovered a China-linked group, UAT-11587, targeting government and policy organizations across Asia, Talos reports.
Targets
- Countries including Taiwan, India, the Philippines and Cambodia
- At least 16 organizations across eight Asian countries by July 2026
- Academic, think-tank and civil society groups working on policy
Talos first saw the activity in September 2025.
The Antino backdoor
- Written in Rust for Windows.
- Can run commands, transfer files, load code in memory and survive reboots.
- Communicates only through Microsoft 365, using Microsoft Graph to talk via Outlook and OneDrive.
How victims were infected
Spear-phishing emails with tailored decoy documents, including one that recreated Gmail's attachment interface, led to a five-stage infection chain. The group relied heavily on Cloudflare infrastructure.
Why it matters
Malware that talks through Outlook and OneDrive blends in with normal office traffic, making it very hard to spot on the network. Talos assesses with high confidence the group is China-nexus.
What defenders should do
- Monitor for unusual Microsoft Graph API use by non-standard applications.
- Train policy staff, who are prime espionage targets, to verify unexpected documents.


