Chinese government-backed hacking groups allegedly targeted artificial intelligence companies and several Asian governments in recent campaigns, according to two new reports this week.
On Thursday, researchers at Proofpoint spotlighted an incident from July where a Chinese threat actor conducted multiple phishing attacks by impersonating prominent economists and even a former member of the White House Office of Science and Technology Policy leadership team.
The emails targeted AI experts who worked for universities, think tanks and law firms. The first emails were sent on July 8 and initially impersonated former White House official Lynne Edwards Parker before switching to prominent foreign police expert Heidi Crebo-Rediker.
The lure in the email was the opportunity to join a fake “AI Policy Advisory Committee” or participate in a fictitious Senate report on AI export controls.
“The group first sent benign conversation starter emails, which included calls to action themed around AI policy such as joining an ‘AI Policy Advisory Committee,’ to build rapport and solicit a response from the target,” Proofpoint researchers said.
Once they got a response, the hackers followed up with a URL redirection chain that tried to steal credentials and more. The malicious links led to a OneDrive credential phishing page designed to get victims to provide their login information.
Proofpoint noted that the same group was previously seen targeting people who work for U.S. and Japanese think tanks, defense contractors and universities.
It typically registered domains impersonating legitimate organizations like The Heritage Foundation, the Japan-Taiwan Exchange Association and the office of Japan’s Defense Minister.
Antino backdoor used in Taiwan, India, Philippines
The Proofpoint report came one day after Cisco Talos published an advisory about a new backdoor used by Chinese state-backed groups to target government organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria.
Cisco incident responders identified 16 organizations that were either affected or targeted across eight different Asian countries between September 2025 and July 2026.
The hackers used a backdoor called Antino that allowed them to conduct reconnaissance, transfer files and maintain their access to victims. The goal of the campaign was intelligence gathering, according to the researchers.
Most victims were initially targeted with phishing emails and decoy documents to lure victims into responding, clicking on links or downloading malicious files.
“Talos first identified [the group’s] campaign while investigating a spear-phishing campaign directed at Taiwan’s academic, think tank, and civil society policy community in March 2026,” Cisco said.
“Further investigation showed that the activity extended beyond the initial Taiwan operation. Talos subsequently identified confirmed or probable affected government and security environments across multiple Asian countries, alongside additional regional targeting supported by lure content.”
The campaign started in the Philippines and continued until the latest wave in June that targeted organizations in India. In total, Cisco found about 350 compromised endpoints across the eight countries.
The hackers used a variety of lures, including news reports about the Trump administration, invitations spoofing real events, legislative documents and more.
Cisco Talos found overlaps with another campaign identified by researchers at Symantec that saw Chinese state hackers using the Antino backdoor.
Click Here For The Original Source.
