China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

Executive Summary

Cisco Talos identified the UAT-11587 threat group, linked to China, targeting government and policy entities in Taiwan, India, the Philippines, and Cambodia. The group delivers a previously undocumented backdoor named Antino, discovered in developer artifacts and used to compromise targeted systems.


Intelligence Metadata - Source Publisher: Cisco Talos - Published Date: 2026-09-30T10:00:01+00:00 - Category: research

Original Description: Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.

"Yesterday is history. Tomorrow is a mystery. And today? Today is a gift that's why they call it the present."

— Unknown
Source: Cisco Talos