Cisco Talos says it first observed UAT-11587 activity in September 2025 and identified the campaign while investigating, in March 2026, spear-phishing aimed at Taiwan’s academic, think tank, and civil-society policy communities. By July 2026, it had identified at least 16 institutional environments affected or targeted in eight Asian countries, including Taiwan, India, the Philippines, and Cambodia. Talos assesses with high confidence that the group is linked to China.
The report describes Antino as a Rust-compiled Windows backdoor with host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading, and persistence capabilities. Its command-and-control channel uses Microsoft Graph to interact with Outlook and OneDrive. The observed chain began with spear-phishing emails and customized decoy documents; Talos also reports extensive use of Cloudflare infrastructure. For the scope, evidence, and qualifications, consult Cisco Talos’s original report and compare its claims with the research it cites. If using AI to study or apply this material, remove personal data and confidential details before submitting it.