UAT-11587 is a Chinese state-sponsored threat group
Assessment
Cisco Talos assesses 'with high confidence that UAT-11587 is China-nexus' based on 'the totality of corroborating technical and operational evidence, rather than any single indicator,' and assesses intelligence-gathering purpose only at moderate confidence. Talos deliberately uses 'China-nexus' rather than 'state-sponsored.' Coverage that labels the group 'suspected Chinese state-sponsored' states the attribution more strongly than the primary source; attribution to a nation state is an assessment, not an established fact.
Where this claim appeared
Security Online · 2026-10-02
https://securityonline.info/uat-11587-antino-backdoor/What “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
UAT-11587 deploys Antino backdoor using Microsoft 365 as dead-drop C2 against Asian governmentsThink this assessment is wrong? Report an error.