Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts. Talos first observed UAT-11587 activity in September 2025. By July 2026, Talos had identified at least 16 affected or targeted institutional environments across eight Asian countries.
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
About this summary. This is a short, independently written summary of an article first published by Cisco Talos. Cyber Security News did not report or verify the underlying story. Read the original: https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/

Source attribution: headline and facts are from Cisco Talos (blog.talosintelligence.com). Summary method: excerpt of the source description. See our source attribution policy.






