
Two new reports this week describe Chinese state-aligned hacking aimed at policy and government circles. Cisco Talos tracks a cluster it calls UAT-11587 that has run espionage campaigns since September 2025, with at least 16 affected or targeted institutions and roughly 350 compromised endpoints across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. Targets include defense, foreign-affairs, legislative and law-enforcement bodies as well as think tanks and civil-society groups. Talos assesses with high confidence the actor is China-nexus.
The group’s custom Rust backdoor, “Antino,” supports reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence. Its command channel runs only through Microsoft 365: Microsoft Graph, Outlook and OneDrive objects act as dead drops, so there is no conspicuous standalone C2 server to block. Delivery starts with tailored spear-phishing and decoys, including a fake Gmail attachment page, followed by a five-stage chain staged on Cloudflare. Emails spoofed trusted senders by exploiting the gap between the SMTP envelope sender (which passed SPF) and the visible From header. Talos found overlap with Symantec’s Jewelbug research but could not confirm the two are the same operation.
Separately, Proofpoint described a July campaign by China-aligned TA419 against AI experts at universities, think tanks and law firms. Emails impersonated a former White House science-policy official and a well-known economist, first sending benign conversation starters about joining an “AI Policy Advisory Committee” or contributing to a fictitious Senate report on AI export controls, then sending a redirect chain to a OneDrive-themed credential phishing page.
How to check if you’re affected
Affected products are mainly Windows endpoints at government, policy and research organizations that received the lures. Defenders can hunt for the following:
- Outlook or OneDrive activity generated through Microsoft Graph by unexpected applications or tokens, and unfamiliar app registrations in your Microsoft 365 tenant.
- Inbound mail where the SMTP envelope domain differs from the visible From domain, especially mail sent via Migadu using
osc-cdn[.]com; enforce DMARC alignment rather than relying on SPF alone. - Staff in AI-policy roles who received invitations to advisory committees or Senate reports from unfamiliar contacts; verify through a known channel before replying or clicking.
Full indicators of compromise are in the Talos and Proofpoint write-ups below.
Sources
- China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor — Cisco Talos
- Hallucinating credibility: China-aligned TA419 impersonates its way into US AI policy — Proofpoint
- Researchers find Chinese hacking campaigns targeting AI firms, Asian governments — The Record
