Two independent reports published this week detail separate, recent campaigns by Chinese government-backed hacking groups targeting artificial intelligence firms, universities, and several Asian governments. The campaigns, which occurred between September 2025 and July 2026, primarily relied on phishing and social engineering tactics to achieve intelligence gathering objectives.
Proofpoint researchers identified a series of phishing attacks in July 2026 that specifically targeted AI experts at universities, think tanks, and law firms. The attackers impersonated prominent figures, including former White House Office of Science and Technology Policy leader Lynne Edwards Parker and foreign policy expert Heidi Crebo-Rediker. Initial emails, sent starting July 8, aimed to build rapport by inviting recipients to join a fictitious "AI Policy Advisory Committee" or contribute to a fake Senate report on AI export controls. Once a response was received, the attackers delivered a URL redirection chain leading to a OneDrive credential phishing page designed to steal login information. This group has a history of targeting U.S. and Japanese think tanks, defense contractors, and universities, often registering domains that mimic legitimate organizations such as The Heritage Foundation and the Japan-Taiwan Exchange Association.
Separately, Cisco Talos published an advisory detailing a new backdoor, dubbed "Antino," used by Chinese state-backed groups against government organizations across eight Asian countries: Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. Cisco incident responders identified 16 affected or targeted organizations between September 2025 and July 2026. The Antino backdoor facilitates reconnaissance, file transfers, and persistent access to victim systems, with intelligence gathering identified as the primary goal.
The Antino campaign typically began with spear-phishing emails and decoy documents designed to entice victims into responding, clicking malicious links, or downloading infected files. Cisco Talos first detected this activity in March 2026 during an investigation into a spear-phishing campaign aimed at Taiwan's academic, think tank, and civil society policy communities. Subsequent investigation revealed the campaign's broader scope, encompassing government and security environments across multiple Asian nations, with additional regional targeting supported by tailored lure content.
The campaign originated in the Philippines and continued through June 2026, with the latest wave targeting organizations in India. In total, Cisco found approximately 350 compromised endpoints across the eight countries. The attackers employed a variety of lures, including news reports related to the Trump administration, invitations spoofing real events, and legislative documents. Cisco Talos also noted overlaps between their findings and a campaign identified by Symantec researchers, which also involved Chinese state hackers utilizing the Antino backdoor.






