UAT-11587 is a China-nexus cyberespionage activity cluster observed since September 2025. It targets government, diplomatic, legislative, law-enforcement, defense, national-security, academic, technology, policy-research, think-tank, and civil-society organizations. Known targeting spans Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. By July 2026, its campaign encompassed at least 16 affected or targeted institutional environments, with approximately 350 compromised endpoints identified. Its China-nexus attribution is supported by targeting patterns, Chinese-language document metadata, development artifacts, and operational indicators; attribution to a specific Chinese organization has not been established. The actor uses highly tailored spear-phishing with political, maritime, diplomatic, legislative, human-rights, and regional-security themes. It spoofs trusted sender identities and recreates Gmail attachment-preview cards in email HTML to direct recipients to malicious content. Observed messages exploit non-enforcing DMARC policies rather than a Gmail vulnerability. A multistage delivery chain uses HTA or Windows Script File stagers, JavaScript downloaders, encrypted payloads, and .NET deserialization before deploying the Antino backdoor through DLL sideloading with a legitimate Microsoft-signed executable. Cloudflare Pages, Cloudflare R2, and Amazon CloudFront support payload delivery, execution tracking, and staging. Antino is a Rust-based Windows backdoor available in 32-bit and 64-bit builds. It supports host and process reconnaissance, directory enumeration, shell and PowerShell execution, file transfer, operator-supplied program execution, in-memory shellcode loading, and persistence. It also employs shellcode sleep masking and abuses Windows Scripted Diagnostics to execute PowerShell through legitimate Windows components. Its native command-and-control communications operate through Microsoft Graph, using Outlook as a command-exchange dead drop and OneDrive for heartbeats, tool delivery, and file exfiltration. Authentication uses an actor-controlled Entra ID application. This reliance on legitimate cloud infrastructure helps malicious communications blend into ordinary Microsoft 365 traffic.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
144 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a campaign affecting roughly 350 endpoints across 16 environments. Used a five-stage infection chain and a Rust backdoor that abused Microsoft cloud services for command and control.
China-nexus cyber-espionage activity targeting government agencies, diplomatic organizations, universities, think tanks and policy groups with the Antino Windows backdoor. By July 2026, researchers had identified at least 16 affected or targeted institutional environments and approximately 350 compromised endpoints. Attribution to a specific Chinese group remains unresolved.
China-linked, reportedly state-sponsored espionage cluster active since September 2025. The campaign targeted at least 16 institutional environments across eight countries, compromising approximately 350 endpoints. It delivers the Rust-based Antino backdoor through spear-phishing and a multistage infection chain, using legitimate cloud services for payload delivery and Microsoft Graph API for command and control.
A China-linked cyberespionage cluster using the Antino backdoor to conduct sustained intelligence collection against Asian government, defense, policy, and civil society organizations. The report describes approximately 350 compromised endpoints across eight countries, including roughly 57 new endpoints in India over two days in June 2026. Talos assesses the cluster as China-nexus with high confidence, but the content does not explicitly identify a state sponsor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.