ThreatPaper
Weak Evidence

The campaign penetrated more than 16 government institutions

Assessment

Cisco Talos reports 'at least 10 confirmed and five probable affected institutional environments, plus one additional intended target' — 16 in total, but only 10 are confirmed compromises, with ~350 endpoints across eight countries. Coverage stating the actor 'penetrated more than 16 confirmed or probable institutional environments' treats probable and merely-intended targets as confirmed penetrations and inflates the count, conflating the institution denominator with the endpoint denominator.

Where this claim appeared

CybernewsAI · 2026-09-30

https://www.cybernewsai.com/blog/china-uat-11587-antino-backdoor-espionage

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

UAT-11587 deploys Antino backdoor using Microsoft 365 as dead-drop C2 against Asian governments

Think this assessment is wrong? Report an error.