Zero Day Room
Live
Vulnerabilities

China-Nexus Actor UAT-11587 Uses Antino Backdoor

Cisco Talos details a China-nexus threat actor, UAT-11587, using a Rust-based backdoor called Antino that leverages Microsoft 365 services for covert communications.

Cisco Talos details a China-nexus threat actor, UAT-11587, using a Rust-based backdoor called Antino that leverages...

A China-nexus threat actor tracked as UAT-11587 is using a sophisticated Rust backdoor that communicates exclusively through Microsoft 365 services. Cisco Talos first detected the actor in September 2025, and by July 2026 it had targeted at least 16 government and policy institutions across eight Asian countries, with a particular focus on Taiwan and regional security themes. The campaign uses Outlook and OneDrive as its primary command-and-control channel.

Talos assesses with high confidence that UAT-11587 is a China-nexus actor. This classification is based on development and preparation-environment indicators, including lure documents with Simplified Chinese metadata and a zh-CN language tag. Spear-phishing message headers also contained a UTC+08:00 time zone offset, which is used across mainland China. The campaign's targeting of foreign affairs and security policy organizations provides further contextual support for this assessment.

Attack chain and initial access

Talos first identified the campaign while investigating a spear-phishing operation directed at Taiwan's academic and policy community in March 2026. The actor used sophisticated social engineering to bypass email security. UAT-11587 spoofed sender identities trusted by the intended recipients to evade SPF and DMARC checks.

Another technique involved replicating Gmail's native attachment preview widget inside the email body. The actor used four inline PNG images embedded as Base64-encoded MIME parts to mimic the styling. This fake widget was wrapped in a link pointing to an attacker-controlled Cloudflare Pages URL. When viewed in a browser, Gmail's renderer displays the attacker's HTML, creating a fake attachment card visually identical to a legitimate Gmail preview. The lures demonstrated extensive reconnaissance, focusing on themes of Taiwanese politics, regional government, maritime issues, and diplomacy.

Infrastructure and tooling

The actor relied heavily on Cloudflare infrastructure for delivery and payload staging. Talos identified a JavaScript downloader associated with UAT-11587 that referenced a known malicious CloudFront domain, d32tpl7xt7175h[.]cloudfront[.]net. This same domain was previously flagged in connection with UNC6384, another China-affiliated threat actor targeting European diplomatic entities.

The final payload is a custom Rust backdoor tracked as Antino. Its native command-and-control channel operates solely through Microsoft 365, using the Microsoft Graph API to interact with Outlook and OneDrive. Antino supports a range of capabilities.

Antino capabilities and Rust build indicators

Technical analysis of the backdoor provided strong links to a mainland Chinese development environment. Ten distinct Antino build outputs contained Cargo registry paths referencing rsproxy.cn. This is a high-speed domestic mirror and proxy service for the Rust package repository crates.io, specifically catering to users within mainland China. The combination of this artifact with the zh-CN language tags and the +08:00 time stamp is more consistent with a mainland Chinese environment than with regions like Taiwan or Hong Kong where Traditional Chinese is predominant.

Campaign scope and overlap with other threats

Attacks linked to UAT-11587 spiked between March and early June 2026. A concentrated wave occurred on June 8 and 9, targeting dozens of systems associated with government IT infrastructure. Evidence also indicates the actor expanded operations to target organizations in Syria around May 2026.

Talos identified overlaps between UAT-11587 and an activity set tracked by Symantec as Jewelbug, a group assessed as China-based hackers-for-hire. Symantec reported that Jewelbug conducted both espionage and cryptocurrency fraud, suggesting a potential link. However, Talos said its own investigation failed to unearth a definitive connection between the UAT-11587 espionage campaign and Jewelbug's financially motivated activity. Symantec assessed that any link likely involved a separate business supplying access and infrastructure rather than a single group performing both roles. By July 2026, Talos had identified at least 16 affected or targeted institutional environments across eight Asian countries.

Related coverage

More from Vulnerabilities