China-Linked Hackers Compromised 350 Systems in Asia
A China-nexus group targeted government and defense networks using an undocumented backdoor between 2025 and 2026.
Updated on Oct. 1, 2026 in Cybersecurity

Between September 2025 and July 2026, a China-nexus threat actor known as UAT-11587 compromised 350 endpoints across Asia. The campaign targeted government, defense, and academic organizations in eight countries using a previously unknown backdoor.
Why it matters
The use of an undocumented Rust-based tool indicates an evolving approach to evading detection in high-value environments. This campaign demonstrates the persistence of state-aligned actors in mapping government and policy-focused infrastructure.
The attackers deployed Antino, an undocumented backdoor written in Rust, to gain access to Windows system endpoints. Talos researchers identified 10 confirmed and five probable institutional targets during the analysis of the 350 compromised systems.
The players
Talos
A global intelligence and research organization that tracks cyber threats and maintains threat detection signatures.
UAT-11587
A China-nexus threat actor group responsible for the espionage campaign against government and academic targets.
The details
The campaign relied on the deployment of Antino, a malicious backdoor that provides remote access to infected Windows endpoints. By utilizing the Rust programming language, which is increasingly favored for its memory safety and ability to produce compact, harder-to-analyze binaries, the attackers minimized their footprint. This approach allowed the group to sustain access across diverse government and civil-society environments in Asia for nearly a year.
Timeline
September 2025: The cyber-espionage campaign activity began.
July 2026: The campaign activity concluded.
The Tech Race
This activity aligns with the broader trend of state-aligned groups developing bespoke, low-visibility tools to target sensitive regional infrastructure. It extends the body of work documented by Talos in identifying novel malware families used to compromise defense and diplomatic networks.
Organizations operating in the defense and academic sectors across Asia should audit Windows endpoints for artifacts related to the Antino backdoor. Defenders should focus on monitoring Rust-based binaries in unauthorized network locations, as this tool represents an emerging threat vector.
The takeaway
The deployment of the Antino backdoor serves as a reminder of the need for robust endpoint monitoring that identifies non-standard process execution. Security teams should monitor future threat reports from Talos for updated indicators of compromise related to UAT-11587.
Further reading
For more on threat intelligence, visit the Cybersecurity section.






