What happened
Two new reports from Proofpoint and Cisco Talos describe Chinese state-backed hacking campaigns targeting AI professionals and government entities in Asia. Proofpoint identified a July phishing operation impersonating officials to lure AI experts, while Cisco Talos documented the use of the 'Antino' backdoor to compromise 350 endpoints across eight countries.
Researchers at Proofpoint reported on a July incident where a Chinese threat actor conducted phishing attacks against AI experts at universities, think tanks, and law firms. The attackers impersonated prominent figures, including former White House official Lynne Edwards Parker and foreign police expert Heidi Crebo-Rediker. The initial emails used benign conversation starters themed around AI policy, such as invitations to join a fake 'AI Policy Advisory Committee' or participate in a fictitious Senate report on AI export controls. Once victims responded, the attackers deployed URL redirection chains leading to OneDrive credential phishing pages to steal login information.
Cisco Talos published an advisory detailing the use of a backdoor named 'Antino' by Chinese state-backed groups targeting government organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. The campaign, active between September 2025 and July 2026, resulted in approximately 350 compromised endpoints across 16 organizations. The backdoor enabled reconnaissance, file transfer, and persistent access. Cisco noted that the campaign initially targeted Taiwan's academic and policy community in March 2026 before expanding to other regions, with lures including spoofed news reports and legislative documents.
Proofpoint noted that the group behind the AI-targeted phishing had previously targeted U.S. and Japanese think tanks, defense contractors, and universities, often registering domains that impersonated legitimate organizations like The Heritage Foundation. Cisco Talos also identified overlaps between the Antino campaign and another campaign previously identified by Symantec researchers, suggesting a coordinated or shared infrastructure among Chinese state-linked hacking groups.
Source details: therecord.media ↗
Why it matters
These campaigns demonstrate a strategic shift in state-sponsored espionage, specifically leveraging AI policy and research as primary lures to access sensitive intellectual property and government data. The targeting of AI experts indicates that AI capabilities are now viewed as critical national security assets, increasing the risk for researchers and policymakers. The widespread deployment of the Antino backdoor across multiple Asian nations highlights the persistent threat to regional digital infrastructure and the need for enhanced security protocols in AI-focused organizations.
The specific targeting of AI experts and the use of AI policy as a lure indicate that state actors are prioritizing the acquisition of AI-related intellectual property and influence over . This represents a significant escalation in the intersection of cybersecurity and AI development, where the technology itself is the primary objective of espionage.
The deployment of the Antino backdoor across eight Asian countries underscores the vulnerability of government and academic institutions to persistent state-sponsored threats. The scale of the compromise, with 350 endpoints affected, suggests a sophisticated and well-resourced operation aimed at long-term intelligence gathering rather than short-term disruption.
These reports highlight the need for AI organizations and government bodies to adopt more robust security measures, particularly in protecting personnel who are high-value targets for state-sponsored phishing. The use of sophisticated social engineering tactics, such as impersonating high-profile officials, requires advanced training and vigilance among researchers and policymakers.
Interactive Mechanism: How It Actually Works
Explore the underlying technology behind this development interactively.
Impossibility results in algorithmic fairness (e.g. Kleinberg et al., Chouldechova) show what?
What to watch next
Monitor for further disclosures regarding the Antino backdoor and potential expansions of the Proofpoint-identified phishing campaigns. Watch for official responses from the targeted governments and AI firms, as well as any new defensive measures or policy recommendations issued by cybersecurity firms in response to these specific AI-targeted threats.
Future reports may reveal the specific data exfiltrated from the compromised endpoints, which could provide insights into the strategic priorities of the Chinese state in the AI sector. Additionally, watch for any legal or diplomatic responses from the targeted countries to these cyber operations.
Cybersecurity firms may release further details on the Antino backdoor's capabilities and potential variants, which could help other organizations identify and mitigate similar threats. The overlap with Symantec's findings may lead to a broader understanding of the infrastructure used by these state-backed groups.
AI companies and research institutions may implement new security protocols or public advisories in response to these campaigns, potentially affecting how AI research is conducted and shared publicly. This could include increased scrutiny of external communications and partnerships.