UAT-11587 Antino spear-phishing campaign against government and policy organizations
Campaign
Summary
Hide ▲
Show ▼
A UAT-11587 spear-phishing campaign is expanding across Asia and Syria, delivering the Antino backdoor to government and policy organizations and increasing the risk of espionage and persistent access. The operation first surfaced in September 2025 and later broadened to targets in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. It uses tailored lures, spoofed trusted senders, and a fake Gmail attachment preview to push victims into a multi-stage infection chain. Antino then abuses Microsoft 365, especially Outlook and OneDrive, for command-and-control and file transfer.
Related Happenings
Antino Windows backdoor activity using Microsoft 365 dead drops
Malware Activity
H score15
First: 02.10.2026 20:33
Last: 02.10.2026 20:33
Sources 1
How related:
"Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence," security researcher Ashley Shen said. "Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive."
About this happening:
Antino is being deployed as a Windows backdoor that gives operators host reconnaissance, command execution, file transfer, and persistence while routing C2...
Antino Windows backdoor activity using Microsoft 365 dead drops
Malware ActivityHow related: "Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence," security researcher Ashley Shen said. "Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive."
About this happening: Antino is being deployed as a Windows backdoor that gives operators host reconnaissance, command execution, file transfer, and persistence while routing C2...
Star Blizzard fake event-invitation phishing campaign
Campaign
H score29
First: 29.09.2026 20:20
Last: 29.09.2026 20:20
Sources 1
About this happening:
Star Blizzard is using the RedFlick delivery chain in 2026 to push the CosmicPulse backdoor through phishing emails and a password-protected archive that leads...
Star Blizzard fake event-invitation phishing campaign
CampaignAbout this happening: Star Blizzard is using the RedFlick delivery chain in 2026 to push the CosmicPulse backdoor through phishing emails and a password-protected archive that leads...
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
Campaign
H score32
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
About this happening:
An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
CampaignAbout this happening: An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
Campaign
H score39
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
CampaignAbout this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
Timeline
-
02.10.2026 20:33 2 articles · 2h ago
UAT-11587 Antino spear-phishing campaign against government and policy organizations
Initial DisclosureThe campaign first surfaced in September 2025 with spear-phishing against Taiwan's academic, think tank, and civil society policy community. That initial phase established the lure themes and access pattern that later broadened across the region.
Show sources
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign — thehackernews.com — 02.10.2026 20:33
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign — thehackernews.com — 02.10.2026 20:33