China-Nexus Spearphish Fakes Gmail Attachments

Cisco Talos · High sophistication
Last updated October 1, 2026

Cisco Talos reports a China-nexus cluster (UAT-11587) using targeted spear‑phishing against government and policy organizations across Asia. The attackers spoof trusted senders and use an email that visually clones Gmail’s attachment preview to trick recipients into clicking a Cloudflare-hosted download link, leading to a multi-stage infection chain that installs the Antino backdoor.

How the attack worked

Cisco Talos documented UAT-11587, a China-nexus cluster conducting targeted spear-phishing against government and policy organizations across Asia, including Taiwan, India, the Philippines, and Cambodia. The group relied on tailored decoy documents and a multi-stage infection chain to gain initial access, rather than a single generic phishing template.

One of the most notable techniques was a visual clone of Gmail's attachment preview placed directly inside the email body. Instead of a real attachment, the entire preview card was wrapped in an anchor tag linking to an attacker-controlled Cloudflare Pages URL. These links included a tracking parameter that allowed per-recipient logging, meaning the attackers could monitor exactly who clicked. The campaign's final payload was a custom Rust backdoor called Antino, which communicates through Microsoft 365 services such as Outlook and OneDrive rather than a dedicated command-and-control server, helping it blend into normal enterprise traffic.

Why it succeeded

The campaign combined two forms of trust abuse. First, sender identities were spoofed so that the visible From header displayed a trusted organization's name, while the actual envelope sender used an attacker-controlled domain sent through Migadu. This misalignment meant messages could still reach inboxes even when DMARC checks failed. Second, the fake Gmail attachment preview exploited a visual interface that recipients see constantly and rarely scrutinize, making the deceptive click feel routine.

Decoy content was also highly tailored, referencing real policy topics and events such as an Indo-Pacific forecast briefing, suggesting the attackers had detailed knowledge of their targets' interests and institutional context.

What to watch for

  • Attachment previews that are actually clickable images or cards embedded in the email body rather than genuine file attachments
  • Links pointing to unexpected cloud-hosting domains like pages.dev, especially with tracking parameters in the URL
  • Sender names that look familiar but whose underlying domain or envelope sender doesn't match the organization
  • Unsolicited event invitations or official-looking documents that closely match a recipient's specific job function

Building resistance

Organizations in government, foreign affairs, defense, and policy research should train staff to verify unexpected requests through a separate known channel, inspect links before clicking rather than trusting familiar-looking preview widgets, and treat highly relevant, well-tailored lures with extra caution rather than reduced suspicion.

Key findings

  • UAT-11587 targeted government and policy organizations across Asia (including Taiwan, India, the Philippines, and Cambodia) beginning in 2025–2026.
  • Initial access repeatedly used spear‑phishing with tailored decoy documents and a multi‑stage infection chain.
  • One delivery method cloned Gmail’s attachment preview inside the email body and linked it to an attacker-controlled Cloudflare Pages URL with per-recipient tracking.
  • The actor spoofed trusted senders using envelope/from misalignment so messages could reach inboxes even when DMARC failed.
  • Final payload included a custom Rust backdoor (“Antino”) that communicates through Microsoft 365 (Outlook/OneDrive) rather than a dedicated command server.

Who’s being targeted

  • Commonly targeted roles: Government staff (public administration), Defense / national security personnel, Foreign affairs / diplomatic teams, Legislative / parliamentary staff, Think tank and policy researchers, University researchers and administrators, Government IT and shared services teams, Civil society / human rights organizations.
  • Affected industries: Defense and national security, Executive government and public administration, Foreign affairs and diplomatic services, Justice and law enforcement, Legislative and parliamentary institutions, Government IT and e-government shared services, Think tanks and policy research, Universities and research institutions, Civil society and human rights organizations.
  • Attack channels: email.
  • Impersonated: A trusted organization known to the recipient (spoofed sender identity), A trusted sender identity displayed in the From header (spoofed), An event organizer or official/government policy source (implied by decoy content).

Red flags to watch for

  • The “attachment” is actually a clickable image/card inside the email body (not a normal attachment)
  • Link goes to an unexpected Cloudflare Pages address (pages.dev) and includes tracking parameters
  • Sender appears familiar, but the underlying sender authentication/domain alignment may be wrong
  • From address/domain doesn’t match the organization’s real domain when inspected closely
  • Unexpected third-party sending service context (message routing) for a sensitive request
  • Unusual urgency or context mismatch for the purported sender
  • Unexpected event/document arriving out of the blue (even if it looks highly relevant)
  • Decoy uses real organizations/experts to appear credible but lacks normal verification steps
  • Attachment/link behavior is unusual (e.g., redirects to cloud-hosted downloads)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is UAT-11587?

UAT-11587 is a China-nexus threat cluster that Cisco Talos observed spear-phishing government and policy organizations across Asia, including Taiwan, India, the Philippines, and Cambodia, starting in 2025.

How did the fake Gmail attachment trick work?

The attackers recreated Gmail's native attachment preview widget inside the email HTML body, and the entire attachment card was wrapped in an anchor tag pointing to an attacker-controlled Cloudflare Pages URL rather than a real file.

How did the sender spoofing bypass DMARC?

Messages were sent through Migadu using an attacker-controlled envelope sender domain while the visible From header showed the impersonated organization's identity, so the receiving provider still accepted the message despite the DMARC failure.

What payload did this campaign deliver?

The infection chain ultimately installed a custom Rust backdoor called Antino, which communicates through Microsoft 365 services like Outlook and OneDrive instead of a dedicated command server.

Read the video transcript

Picture this: you get an email that looks like Gmail, with a familiar contact and a clean attachment preview card. But in recent attacks on policy teams across Asia, that ‘attachment’ was just a fake Gmail widget. The whole card was one big link to a Cloudflare Pages download, kicking off a multi-stage Antino backdoor infection that hides inside Microsoft 365 traffic. Here’s the catch: the sender name looks trusted, but the real sending domain is different, and the ‘attachment’ sits inside the message. Hover it and you see a pages.dev link with tracking parameters, not a normal file or your organization’s domain. If an email shows a Gmail-style attachment card that opens a pages.dev link, stop. Don’t click it, forward it to security and confirm the file through your usual channel instead.

Similar attacks

Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake CAPTCHA Trick Fuels WebDAV Malware Chain

Fake CAPTCHA Trick Fuels WebDAV Malware Chain

Cisco Talos investigated a real incident at a Ukrainian government organization and found a complex WebDAV-based infection chain linked to a Russian actor (UAT-10820). The campaign uses fake CAPTCHA/verification prompts to manipulate users into copying and pasting commands, leading to credential…

September 10, 2026
Gambling Goblin Hijacks Gov Sites for Phishing

Gambling Goblin Hijacks Gov Sites for Phishing

Researchers say a Chinese-speaking cybercrime group compromised Brazilian government and education websites and used them as “trusted” entry points to quietly redirect visitors to attacker-run phishing pages. The fake pages impersonated well-known app stores (Google Play, Microsoft Store, Amazon)…

September 2, 2026
Fake IT Support on Teams Drops TWINLOOT

Fake IT Support on Teams Drops TWINLOOT

Researchers observed an active campaign where attackers used Microsoft Teams to impersonate IT support and trick a user into running a PowerShell command. That action downloaded a malicious package that enabled credential theft (via a fake lock screen) and helped attackers move through internal…

August 18, 2026
Fake Defense Summit Invites Hit Dutch Police

Fake Defense Summit Invites Hit Dutch Police

A Russian-linked group allegedly stole sensitive contact data from the Netherlands National Police after getting access to an employee’s email account. The podcast describes a realistic spearphishing lure: an email invitation to a “European Defence Summit” that includes a link or a QR code in a PDF…

July 23, 2026
Browser Scams: ClickFix, OAuth & Session Theft

Browser Scams: ClickFix, OAuth & Session Theft

The article describes how real-world attackers are shifting common breach activity into the web browser, including phishing that steals live sessions, fake “copy/paste to fix” prompts (ClickFix), and OAuth consent/device-code tricks. It highlights how these browser-based lures can bypass MFA and…

September 30, 2026