Cisco Talos

Chi En (Ashley) Shen

Chi En (Ashley) Shen

2026

It’s Me, Myself and (A)I: Hunting UAT-11587’s Cloud-Abuse Campaigns Across Asia

In early 2026, we investigated a spear-phishing campaign targeting a Taiwanese organization. The emails delivered a previously undisclosed Rust-based malware family that abuses OneDrive and Outlook mailboxes as command-and-control channels. By pivoting from the malware samples and infrastructure used in the campaign, we uncovered a much broader targeting scope: more than 200 victims across think tanks, non-profit organizations, and entities in the Philippines, Pakistan, India, Taiwan, Syria, Myanmar, Cambodia, and Vietnam. Several decoy documents also indicated potential interest in the Middle East. During our analysis, we identified artifacts linked to Mustang Panda; we are currently tracking this activity cluster as UAT-11587.

This investigation provides the first intelligence into UAT-11587’s proprietary malware, operational workflow, campaign timeline, timezone patterns, and use of “vibe coding” techniques. We will demonstrate how we leveraged AI agents throughout the investigation, from campaign tracking and infrastructure analysis to malware reverse engineering. This includes analyzing the threat actor’s technique for bypassing SPF checks, reverse engineering the Rust-based malware, and using AI to develop both a decryptor and an protocol emulator to support communication-protocol analysis.

The talk will conclude with an assessment of the actor profile and a discussion of how AI can be effectively leveraged in threat investigations. Attendees will leave with a detailed understanding of UAT-11587’s tradecraft, malware family, and indicators of compromise to support detection, hunting, and mitigation.


About Chi En (Ashley) Shen

Chi-en Shen (Ashley) is security researcher at Cisco Talos. She specializes in researching emerging threats, including APTs, financially motivated crimes, spyware, and exploitation carried out by mercenary groups. Previously, she worked as a security engineer at Google Threat Analysis Group, where she focused on zero-day exploit hunting and tracking botnets. Prior to that, she was a member of the Mandiant, where she tracked APT groups in APAC and contributed to the development of the Threat Intelligence platform. 

Passionate about supporting women in InfoSec, Ashley co-founded HITCON GIRLS, the first security community for women in Taiwan. Additionally, she serves as an organizer for Rhacklette, a security community for FINTA in Switzerland. To support the security community, Ashley serves as a review board member for Black Hat USA , BlueHat and HITCON conferences. She has also shared her expertise as a speaker at conferences such as Black Hat, HITCON, FIRST, CODE BLUE.