Two reports published this week describe recent Chinese state-linked hacking campaigns. Proofpoint detailed a phishing operation from July targeting AI experts, while Cisco Talos documented a backdoor campaign against Asian government organizations.

According to Proofpoint, attackers impersonated economists and a former White House science and technology official. The emails invited targets to join a fake AI policy advisory committee or contribute to a fictitious Senate report on AI export controls. Victims who responded were led through a URL redirection chain to a OneDrive login page designed to steal credentials. The same group had previously targeted think tanks, defense contractors, and universities in the U.S. and Japan.

Cisco Talos, in a separate report, described a backdoor called Antino used against government and security environments in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. The researchers identified 16 affected or targeted organizations and about 350 compromised endpoints between September 2025 and July 2026. The campaign used phishing emails and decoy documents to deliver the backdoor, which enabled reconnaissance, file transfer, and persistent access. The goal was intelligence gathering.

The two reports are separate but share a common thread: both attribute the activity to Chinese state-backed groups and both show phishing as the initial access method. The source article notes that Cisco found overlaps between its Antino findings and a separate Symantec campaign, but does not indicate any direct connection between the Proofpoint and Cisco operations.