China-Linked Hackers Use Fake Gmail Attachments to Plant Stealthy Backdoor
Cisco Talos researchers have uncovered a cyber espionage campaign by a China-linked group known as UAT-11587, which has been targeting government, academic and civil society organisations across Asia. The campaign was first spotted in March 2026 when attackers sent spear-phishing emails to Taiwan's policy and think tank community, using a fake Gmail attachment interface to lure victims into a multi-stage, cloud-hosted infection chain.
One of the group's key tools is a custom backdoor written in Rust, dubbed Antino. Rather than relying on an obvious dedicated command server, which is easier for defenders to spot and block, Antino communicates through legitimate Microsoft 365 services, using Outlook and OneDrive as hidden drop-off points for stolen data and instructions. This makes the malicious traffic much harder to distinguish from normal business activity.
Talos found that the campaign extends well beyond Taiwan, with confirmed or likely victims in government and security-related organisations across multiple Asian countries. The researchers also noted overlaps with a separate espionage effort reported by Symantec, known as Jewelbug, though Talos has chosen to track UAT-11587 as a distinct activity cluster while investigations continue.