China-Linked UAT-11587 Espionage Campaign Hits 16 Groups in 8 Countries

Medium · Security Affairs ·

Key points

  • UAT-11587 is assessed as a China-linked APT.
  • The operation has touched 16 organizations across 8 countries.
  • Targets include government bodies and policy-focused organizations.
  • Initial access and control rely on Microsoft 365 email, with the Antino backdoor for persistence.
  • No CVE is tied to the campaign, so detection must focus on behavior and email telemetry.

Cisco Talos and Microsoft have attributed a continuing espionage operation to UAT-11587, a group assessed as a China-linked advanced persistent threat. The activity has affected 16 organizations in 8 countries, with government agencies and policy-focused groups among the intended targets. Rather than exploiting a known software flaw, the operators have abused Microsoft 365 email as a command-and-control channel and deployed the Antino backdoor for deeper access. No CVE has been associated with this campaign.

The timeline begins in September 2025 and extends to a July 2026 reference point in the available reporting. That duration suggests a patient, low-noise intrusion set rather than a smash-and-grab operation. The use of ordinary email traffic for C2 can help the intruders blend into routine business communications, making anomalous mailbox activity easy to overlook. Espionage against policy organizations is especially sensitive because it can expose internal deliberations, stakeholder positions, and pre-decisional material.

For K-12 and government defenders, the medium severity rating reflects a targeted espionage threat rather than destructive malware. The absence of a CVE means patching alone will not close the door. Detection depends on identity, email, and endpoint visibility: unusual sign-ins, new mailbox rules, suspicious application consents, and outbound messages that look like normal correspondence but carry control instructions. The Antino backdoor adds persistence and remote access, so host-level hunting is also necessary.

What to watch: any expansion beyond the initial 16 organizations or 8 countries, new email-based C2 patterns, and fresh Antino indicators published by Cisco Talos or Microsoft. Administrators should treat Microsoft 365 telemetry as a primary sensor and correlate it with endpoint alerts. Because the campaign targets government and policy work, staff awareness and rapid reporting of suspicious email remain important complements to technical controls.

What to do now

  1. Review Microsoft 365 audit logs for anomalous sign-ins, mailbox rule creation, forwarding, and OAuth application consents; prioritize accounts tied to policy, legal, and executive functions.
  2. Hunt endpoints for Antino backdoor indicators using Cisco Talos and Microsoft guidance, and isolate any host showing persistence or unusual outbound connections.
  3. Enforce phishing-resistant MFA and conditional access, block legacy authentication, and restrict mailbox access from unfamiliar locations or devices.
  4. Monitor outbound and internal email for C2-like patterns, including encoded content, irregular senders, and messages that trigger no user action.
  5. Limit local admin rights, segment sensitive policy and government networks, and ensure endpoint detection and response is deployed and alerting.
  6. Brief staff on targeted phishing and social engineering, with a fast path to report suspicious messages to IT.
  7. Track vendor updates from Cisco Talos and Microsoft, and review the 16-organization/8-country scope for any sector or regional overlap with your agency.

Original source

Security Affairs

Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news