Cybersecurity Research

China-Linked Hackers Use Fake Gmail Attachments to Plant Stealthy Backdoor

Cisco Talos · 30 Sept 2026
Key Takeaway Businesses that rely on Microsoft 365 should closely monitor for unusual Outlook and OneDrive activity, since attackers are increasingly hiding malicious communications inside trusted cloud services.

Cisco Talos researchers have uncovered a cyber espionage campaign by a China-linked group known as UAT-11587, which has been targeting government, academic and civil society organisations across Asia. The campaign was first spotted in March 2026 when attackers sent spear-phishing emails to Taiwan's policy and think tank community, using a fake Gmail attachment interface to lure victims into a multi-stage, cloud-hosted infection chain.

One of the group's key tools is a custom backdoor written in Rust, dubbed Antino. Rather than relying on an obvious dedicated command server, which is easier for defenders to spot and block, Antino communicates through legitimate Microsoft 365 services, using Outlook and OneDrive as hidden drop-off points for stolen data and instructions. This makes the malicious traffic much harder to distinguish from normal business activity.

Talos found that the campaign extends well beyond Taiwan, with confirmed or likely victims in government and security-related organisations across multiple Asian countries. The researchers also noted overlaps with a separate espionage effort reported by Symantec, known as Jewelbug, though Talos has chosen to track UAT-11587 as a distinct activity cluster while investigations continue.

cyber espionage phishing Microsoft 365 security China-linked threat actor backdoor malware
Primary source law-out.mof.gov.tw ->

Summarised by CISO AI from Cisco Talos. We link back to every original so you can read it yourself.