Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Antino Backdoor Hides Its Entire Command Channel Inside Microsoft 365
Antino Backdoor Hides Its Entire Command Channel Inside Microsoft 365
Read Time:3 Minute, 33 Second

A newly documented Windows backdoor named Antino uses Microsoft 365 as its complete native command-and-control channel, turning ordinary Outlook messages and OneDrive files into an operating system for espionage. Cisco Talos attributes the campaign it tracks as UAT-11587 to a China-linked actor with high confidence and says the operation has targeted government, defense, diplomatic, academic and policy organizations.

The campaign began in September 2025. By July 2026, investigators had identified approximately 350 compromised endpoints across eight countries, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. Talos counted ten confirmed institutional victims, five probable affected environments and one intended target. The observed objectives were consistent with intelligence gathering rather than financial theft.

Outlook carries commands while OneDrive moves data

Antino is written in Rust and is available as both an executable and a library. Its defining feature is the use of Microsoft Graph, the API applications use to communicate with Microsoft services. Outlook transports tasking and results, while OneDrive holds registration records, health updates, stolen documents and tools supplied by the operator.

Newer samples authenticate through an Entra ID application using stored application credentials, so they do not need an interactive user sign-in. The malware checks an attacker-controlled Outlook mailbox about every ten seconds and reads commands from message bodies. Responses are posted in a way that lets the operator associate output with individual tasks.

Every minute, the implant writes a OneDrive status file containing details such as the computer name, username, platform, session identifier and campaign code. Separate cloud folders receive exfiltrated files or deliver new components. The backdoor can survey a machine, launch shell and PowerShell commands, transfer data, execute programs and load additional code directly into memory.

Trusted cloud services complicate network detection

Because communications terminate at widely used Microsoft infrastructure, conventional controls that look mainly for connections to suspicious command servers may see only familiar cloud traffic. That does not make the activity invisible. Unusual Graph application credentials, mailbox polling, repetitive OneDrive file operations and endpoint behavior can still reveal the intrusion when identity, cloud and device telemetry are investigated together.

An optional concealment feature encrypts a secondary in-memory payload while it sleeps, reducing the window in which some memory scanners can recognize that component. It does not hide the entire Antino process and should not be treated as a guarantee of endpoint-detection evasion.

Tailored phishing opens the infection chain

The operators used carefully researched email themes involving legislation, taxation, maritime disputes, policy events and government administration. Some messages imitated Gmail’s attachment-preview card; the apparent document actually directed victims to an attacker-controlled download. In one example, authentication passed for the attacker’s real sending domain but the visible sender identity differed. DMARC detected the mismatch, yet a monitoring-only policy still allowed the message through.

A recurring multistage chain combined Windows scripting, encrypted JavaScript and unsafe .NET object processing to launch a downloader in memory. A decoy document appeared to the user while a signed Microsoft executable loaded a malicious library placed beside it, a DLL-sideloading technique that gave the payload a trusted-looking host. Antino also abused Windows troubleshooting components to execute PowerShell and establish startup persistence.

Defenders need cloud and endpoint context

  • Review Entra ID applications and credentials that access Outlook or OneDrive without user interaction.
  • Alert on unexpected Graph activity from servers or workstations that normally do not automate mailboxes.
  • Enforce DMARC rejection where business conditions allow, and investigate display-name mismatches.
  • Monitor script hosts, DLL sideloading, suspicious registry persistence and troubleshooting-tool abuse.
  • Use the published file, domain and URL indicators for scoped hunting, then pivot to behavior to find variants.

The campaign demonstrates a broader monitoring gap: trusted software-as-a-service traffic cannot automatically be considered benign. Blocking Microsoft 365 would be impractical for most organizations, so defenders need baselines that distinguish legitimate business automation from machine-speed mailbox polling and unusual file exchanges.

The detailed Cyber Security News account includes the indicators and summarizes Talos’s attribution assessment. Organizations in the targeted sectors should combine those indicators with identity audit logs, endpoint timelines and phishing telemetry, because a cloud-native control channel may leave its clearest evidence across several systems rather than in a single network alert.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Antino Backdoor Hides Its Entire Command Channel Inside Microsoft 365, use the discussion on Forum.

>> forum community

Comments

Leave a Reply