talos · Crawled Oct 3, 2026
Give yourself room to be human
15 IoCs
Read original article ↗
AI Summary
Cisco Talos identified a threat actor group, UAT-11587, linked to China, targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia. The campaign delivers a previously undocumented backdoor named 'Antino', identified from developer artifacts. The actors are using targeted malware deployments, with specific malicious files observed in telemetry. This activity represents a focused espionage effort against high-value geopolitical targets.
AI-extracted · verify before operational use
Indicators of Compromise 15 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | Details → |
| MD5 | 2915b3f8b703eb744fc54c81f4a9c67f | Details → |
| Filename | sample.exe | Details → |
| SHA-256 | 96fa6a7714670823c83099ea01d24d6d3ae8fef027f01a4ddac14f123b1c9974 | Details → |
| MD5 | aac3165ece2959f39ff98334618d10d9 | Details → |
| Filename | d4aa3e7010220ad1b458fac17039c274_63_Exe.exe | Details → |
| SHA-256 | 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 | Details → |
| MD5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | Details → |
| Filename | tmp00055df5.dll | Details → |
| SHA-256 | 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8 | Details → |
| MD5 | d65c7b544a97b0c3f2773b5fcc57d30e | Details → |
| Filename | f_006048.exe | Details → |
| SHA-256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | Details → |
| MD5 | 38de5b216c33833af710e88f7f64fc98 | Details → |
| Filename | SECOH-QAD.exe | Details → |