China-linked hackers phish AI experts, hit Asian governments
Chinese state-backed hackers have been going after artificial intelligence experts in the West and government bodies across Asia, according to two separate reports published this week by Proofpoint and Cisco Talos.
The campaigns differ in their targets and tools. Both rely on carefully crafted phishing emails as the way in.
Fake AI advisory committee used as bait
Proofpoint described a July operation in which a Chinese threat actor posed as well-known economists and as a former leadership member of the White House Office of Science and Technology Policy, the unit that advises the US president on science and technology matters.
The targets were AI specialists working at universities, think tanks and law firms. The first emails went out on July 8. At first they impersonated former White House official Lynne Edwards Parker. Later the attackers switched to impersonating Heidi Crebo-Rediker.
The emails invited recipients to join an "AI Policy Advisory Committee" that did not exist, or to contribute to a made-up Senate report on AI export controls.
"The group first sent benign conversation starter emails, which included calls to action themed around AI policy such as joining an 'AI Policy Advisory Committee,' to build rapport and solicit a response from the target," the Proofpoint researchers said.
The malicious stage began only after a target replied. The attackers then sent a URL that passed through a chain of redirects and ended on a fake OneDrive login page built to capture credentials.
Proofpoint said the same group has previously gone after staff at US and Japanese think tanks, defense contractors and universities. It usually registers domains that mimic real organizations, including The Heritage Foundation, the Japan-Taiwan Exchange Association and the office of Japan's Defense Minister.
Antino backdoor spreads across eight countries
One day before the Proofpoint report, Cisco Talos published an advisory on a new backdoor called Antino. Chinese state-backed groups used it against government organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria.
Cisco's incident responders counted 16 organizations that were affected or targeted in those eight countries between September 2025 and July 2026. In total, they found about 350 compromised endpoints.
Antino lets the attackers carry out reconnaissance, move files and keep access to compromised systems. The researchers said the campaign's aim was intelligence gathering.
Most victims were first approached with phishing emails and decoy documents meant to get them to reply, click a link or download a malicious file. The lures included news stories about the Trump administration, invitations spoofing real events and legislative documents.
"Talos first identified [the group's] campaign while investigating a spear-phishing campaign directed at Taiwan's academic, think tank, and civil society policy community in March 2026," Cisco said.
"Further investigation showed that the activity extended beyond the initial Taiwan operation. Talos subsequently identified confirmed or probable affected government and security environments across multiple Asian countries, alongside additional regional targeting supported by lure content."
The activity began in the Philippines. The most recent wave, in June, hit organizations in India. Cisco Talos also noted overlaps with a campaign reported by Symantec, in which Chinese state hackers were likewise seen using Antino.
Our Take
Both reports show that a well-timed email still works for state-backed espionage. The Proofpoint campaign did not open with malware. It opened with flattery and a plausible invitation, and it waited for a reply before sending anything harmful. This "rapport first" approach resembles tactics we have covered from Russia's Star Blizzard, which has scaled up its phishing against Ukraine backers using similar social engineering.
The choice of AI policy as bait matters. It suggests that AI export controls and policy debates have become intelligence priorities. Researchers, lawyers and think tank staff in this field should treat unsolicited committee invitations with suspicion, even when they appear to come from known names. They should also verify such offers through a separate channel before clicking any links.
On the Asian side, the timeline is the notable part. The Antino campaign ran for close to a year across eight countries before it was publicly detailed. Together with recent concern over Chinese intrusions such as Salt Typhoon, this points to patient, wide-ranging collection efforts.
It is worth watching whether more vendors link their own findings to Antino, as Symantec's overlap already hints. Another open question is whether the AI-themed lures move beyond credential theft to malware delivery.
