Full Report
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
Analysis Summary
# Threat Actor: UAT-11587
## Attribution & Identity
* **Actor Identification:** UAT-11587 is a China-nexus threat actor characterized by high-confidence attribution based on linguistic evidence (Simplified Chinese metadata/zh-CN language) and operational time zones (UTC+08:00).
* **Aliases:** Currently tracked by Cisco Talos as **UAT-11587**.
* **Associated Groups:**
* Exhibits overlaps with **Jewelbug** (though Talos distinguishes UAT-11587 from Jewelbug's financially motivated activities).
* Shares tactical similarities with **CL-STA-0049**, **Earth Alux**, **Ink Dragon**, and **REF7707**.
* Linked via shared infrastructure to **UNC6384**.
## Activity Summary
* **Detection Timeline:** First detected in September 2025.
* **Recent Campaigns:** A significant escalation occurred between March and June 2026, including a "concentrated wave" on June 8–9, 2026, targeting government IT infrastructure.
* **Current Operations:** Orchestrating a new campaign involving the deployment of the previously undocumented **Antino** backdoor through sophisticated spear-phishing.
## Tactics, Techniques & Procedures
* **Initial Access:** Highly tailored spear-phishing using extensive reconnaissance. Techniques include spoofing trusted sender identities to bypass SPF/DMARC.
* **Social Engineering:** Replicated Gmail's native attachment preview widget within email HTML bodies using Base64-encoded MIME parts to deceive users.
* **Execution:** Use of JavaScript downloaders and Rust-compiled payloads.
* **Persistence:** Achieved via the Antino backdoor.
* **C2 Communication:** Native command-and-control operates exclusively through Microsoft 365 services, utilizing the Microsoft Graph API to interact with **Outlook and OneDrive**.
* **Capabilities:** Host reconnaissance, shell/PowerShell execution, file transfer, and in-memory shellcode loading.
## Targeting
* **Sectors:** Government and policy organizations, academic institutions, think tanks, civil society, maritime, diplomatic, and security entities.
* **Geography:** Primarily Asia (Taiwan, India, Philippines, Cambodia, Pakistan, Thailand, Myanmar). Also expanded to Syria and European diplomatic entities (via associated clusters).
* **Victims:** 16 entities across eight Asian countries; specifically mentioned are Taiwanese political, legislative, and civil defense research subjects.
## Tools & Infrastructure
* **Malware:**
* **Antino:** A custom Rust-based Windows backdoor.
* **JavaScript Downloader:** Associated with initial delivery.
* **Infrastructure:**
* **Microsoft 365/Graph API:** Used for C2 (Outlook/OneDrive).
* **rsproxy[.]cn:** Domestic Chinese mirror for Rust Cargo registry paths.
* **d32tpl7xt7175h.cloudfront[.]net:** CloudFront domain used for delivery.
## Implications
UAT-11587 represents a sophisticated espionage threat that leverages legitimate cloud services (Microsoft 365) to mask malicious C2 traffic. The actor's ability to spoof trusted identities and replicate legitimate UI elements (Gmail previews) indicates a high level of social engineering maturity. Their focus on regional maritime and diplomatic policy suggests alignment with Chinese strategic geopolitical interests.
## Mitigations
* **Advanced Email Filtering:** Implement security solutions capable of inspecting HTML bodies for embedded Base64-encoded elements and replicated UI components.
* **API Monitoring:** Monitor for unusual activity or unauthorized applications interacting with the **Microsoft Graph API**, specifically Outlook and OneDrive usage within the enterprise environment.
* **Endpoint Defense:** Deploy EDR solutions capable of detecting Rust-compiled binaries and in-memory shellcode execution.
* **User Training:** Educate staff on advanced phishing techniques, such as spoofed attachments that do not behave like standard file downloads.