Cisco Talos said a group it calls UAT-11587 sent targeted phishing emails to government and security-linked bodies in Asia. Talos began after a March 2026 message aimed at Taiwan's policy community. It saw activity from September 2025 to July 2026. By July, it had found at least 10 confirmed and five probable affected institutions. It also found about 350 infected devices across eight countries. Talos is moderately to highly confident the targets sat in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria.
Talos has high confidence the group is China-nexus, meaning linked to China. It has moderate confidence the aim is spying. Symantec's Jewelbug research overlaps with this activity. Talos could not confirm a tie to Jewelbug's fraud, so it tracks UAT-11587 on its own. The sources do not name victims or say what data was taken.
Its backdoor, Antino, is written in Rust. Its newer version signs in with an app registered in Entra ID, Microsoft's identity service. Commands pass through an Outlook mailbox. Check-in notes and files go through OneDrive. All traffic ends at two Microsoft domains that many firms allow. A domain allowlist therefore cannot tell it from normal work. Defenders must watch which apps use Microsoft Graph and what they reach. Do we log that, and who reviews it?