Chinese State-Linked Hackers Target AI Experts and Asian Governments in New Phishing and Backdoor Campaigns
Security researchers at Proofpoint have detailed a phishing campaign in which a Chinese threat actor impersonated well-known economists and a former White House official to target artificial intelligence experts at universities, think tanks and law firms. The attackers built trust by first sending friendly emails inviting targets to join a fake 'AI Policy Advisory Committee' or contribute to a fictitious Senate report on AI export controls, before sending malicious links designed to steal Microsoft login credentials. The same group has previously impersonated organisations such as The Heritage Foundation and Japanese government offices to target think tanks, defence contractors and universities.
Separately, Cisco Talos published findings on a newly identified backdoor called Antino, used by Chinese state-backed hackers to infiltrate government organisations across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. Between September 2025 and July 2026, incident responders identified 16 affected or targeted organisations across eight countries. The backdoor allowed attackers to conduct reconnaissance, transfer files and maintain long-term access, with intelligence gathering as the apparent goal.
Together, these reports highlight a continued pattern of state-sponsored actors using carefully crafted social engineering and custom malware to infiltrate organisations involved in policy, research and government work across the Asia-Pacific region.