MediumII Cyber Warfare & Critical Infrastructure1 October 2026, Thursday
China-linked group breached about 350 devices in eight Asian countries
Cisco Talos disclosed on 30 September that the China-linked group UAT-11587 planted a backdoor called Antino on about 350 devices in eight countries between September 2025 and July 2026. On 1 October Proofpoint announced a separate pro-China phishing campaign aimed at AI policy experts.
According to Talos, UAT-11587 spent ten months targeting defence and foreign ministries, parliaments and think tanks in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. Talos wrote that the environments of 15 organisations had been compromised or were very likely compromised; The Record, citing the same report, referred to 16. The largest single incident occurred on 8–9 June, when about 57 new devices appeared in India. The backdoor, software that gives hidden and persistent access to a system, supports nine commands. Every ten seconds it uses Outlook and OneDrive, via Microsoft 365, as its command channel.
The Record said the campaign was first spotted in March 2026 through targeted phishing emails aimed at academic and policy circles in Taiwan. According to a Proofpoint report on 1 October, the pro-China group TA419 has impersonated a former White House science policy official and a foreign policy expert since 8 July. The group invited targets to join a fake AI policy advisory board or to contribute to a fictitious Senate report on AI export controls. The Register reported that the group had also impersonated an Anthropic executive in February 2026, with the aim of stealing Microsoft 365 credentials. The two reports reviewed do not clearly state Proofpoint's confidence level in its attribution.
Talay assessment
Bottom line
Read together, the two reports show China-linked groups gathering information both from Asian governments and from the US debate on AI export controls. Staying undetected for ten months on about 350 devices in eight countries shows how the use of legitimate cloud services as a command channel makes detection harder. Policy circles are likely to remain targets ahead of US–China contacts in October.
Likely effects
- Asian government networksNegative1–6 months
Documents leaked from foreign ministries, defence bodies and parliaments could expose the negotiating positions of countries such as Taiwan and India to the other side.
- AI policy circlesNegativeWeeks
Targeting the accounts of experts involved in the export control debate raises the risk that internal views on US chip policy will leak.
- Cloud securityUncertain1–6 months
The use of Microsoft 365 as a command channel shows that domain blocking alone cannot protect organisations, making behaviour-based monitoring essential.
- TürkiyeUncertainWeeks
The same method could be used against Turkish public bodies through their use of Microsoft 365; the indicators published by Talos should be scanned for on local networks.
Possibilities, ranked
- 1Campaign continues60%
The group changes its infrastructure and keeps targeting Asian governments, and new victims come to light.
Watch: New reports on Antino from Talos, Symantec or the Taiwanese authorities
- 2Official attribution and response30%
One of the affected governments formally attributes the attack to China and takes diplomatic or legal action.
Watch: An official statement from Taiwan, India or the Philippines
- 3Activity stops10%
After the disclosure the group abandons this cluster entirely, and no new incidents are reported.
Watch: No new detections carrying the Antino signature before the end of the year
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- Countries affected▼ 8
- Devices compromised▼ ~350
- Organisations affected▼ 15–16
Sources
- Cisco Talos — China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
- The Record — Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
- The Register — Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing