A new espionage campaign tracked by Cisco Talos has exposed a sophisticated Windows backdoor, nicknamed Antino, that uses Microsoft 365 services as its covert communications channel. Targeting government and policy organizations across Asia — including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar — the activity centers on highly tailored spear‑phishing lures and a multi-stage infection chain that culminates in a Rust-compiled implant communicating through Outlook and OneDrive. The campaign demonstrates an increasing trend: threat actors avoiding traditional, easily-blocked command-and-control servers by abusing trusted cloud platforms.
What Antino is and what it can do
Antino is a Rust-compiled Windows backdoor with a broad set of capabilities: host reconnaissance, listing running processes, directory enumeration, execution of cmd.exe and PowerShell, in-memory shellcode loading, file transfer, and persistence. The implant is delivered as “slc.dll” and launched via DLL sideloading using a legitimately signed Microsoft binary (GatherOsState.exe), which helps it blend into normal system activity. Rather than using a direct C2 server, Antino leverages Microsoft Graph to interact with Outlook and OneDrive, fetching commands, sending heartbeats, and moving files through those services — effectively turning trusted enterprise apps into dead drops.
How the intrusion chain works
The campaign follows a carefully choreographed five-stage infection chain:
- A phishing email leads to a Cloudflare Pages URL that downloads an HTA or WSF stager.
- The stager executes a JavaScript downloader and decryptor.
- A .NET deserialization chain loads a component named TestAssembly.dll, which performs three actions: it opens the decoy lure document, drops a decoy Calculator executable, and downloads and launches the Antino backdoor.
- The Antino implant (slc.dll) is sideloaded via a signed Microsoft executable, then begins communicating through Microsoft 365.
This multi-tiered chain lets the operator stage believable decoys while the real payload runs covertly in the background.
Abusing Microsoft 365: Outlook and OneDrive as covert channels
Antino’s C2 design is noteworthy for how it uses Microsoft 365:
- Outlook is used to retrieve commands: the implant polls a threat-controlled Outlook mailbox folder every ~10 seconds, looking for messages with subjects prefixed like “command_req_[session_id]”.
- OneDrive acts as the channel for heartbeats and file transfers.
By relying on Microsoft Graph and the normal appearance of Outlook/OneDrive traffic, Antino reduces the likelihood of network-layer detection, since the communications resemble legitimate cloud service usage.
Social engineering and initial access techniques
The adversary behind the campaign invests heavily in reconnaissance and social engineering. In several cases attackers spoofed trusted sender identities to bypass SPF/DMARC and increase delivery to inboxes. They also reconstructed Gmail’s native attachment preview widget inside email HTML using inline Base64-encoded PNGs, producing a fake attachment card that looks indistinguishable from a legitimate preview. When victims click the fake widget, they are directed to the attacker-controlled URL hosting the HTA/WSF stager. These contextualized lures targeted audiences interested in foreign affairs, maritime security, and policy research — consistent with intelligence collection goals.
Attribution, indicators, and geopolitical context
Cisco Talos designates the cluster as UAT-11587 and assesses a China nexus with high confidence, citing Simplified Chinese metadata, zh-CN language artifacts in lure documents, and UTC+08:00 timestamping on spear-phishing headers. Additional telemetry includes Cargo build paths referencing rsproxy[.]cn (a China-oriented crates.io mirror) and a JavaScript downloader that contacted a CloudFront domain previously associated with other China-affiliated campaigns. While UAT-11587 has some technical and tactical similarities to groups such as Jewelbug and other China-aligned clusters, Talos treats it as a distinct activity set. The campaign primarily affected Asian government and policy organizations and had a concentrated surge of activity between March and early June 2026, with a notable spike on June 8–9.
Tactics that complicate detection
Antino combines living-off-the-land techniques with signed binary sideloading and cloud service abuse, complicating attribution and detection:
- DLL sideloading through a Microsoft-signed executable reduces suspiciousness in process trees.
- Using Microsoft Graph to call Outlook and OneDrive hides C2 in normal cloud telemetry.
- Execution via Windows Scripted Diagnostics and legitimate Windows components allows the actor to run PowerShell under recognizable system processes, obscuring the origin of malicious activity.
Despite those evasions, observable artifacts remain — file creation, registry changes, PowerShell execution traces, and unusual mailboxes or OneDrive files associated with poorly understood accounts — that defenders can use for detection.
Mitigations and defensive recommendations
Organizations can reduce the risk posed by Antino-style campaigns with layered defenses:
- Strengthen email defenses: enforce SPF/DKIM/DMARC, enable advanced anti-phishing protections, and inspect HTML emails for suspicious embedded content or external links.
- Harden Microsoft 365: monitor for unusual mailbox activity, apply conditional access policies, log Microsoft Graph API usage, and alert on mailboxes that receive high-frequency, automated messages or oddly patterned subject lines.
- Endpoint controls: block or restrict DLL sideloading patterns, use application allowlisting, enable script-blocking policies (or constrain PowerShell to constrained language mode), and deploy EDR solutions tuned to detect in-memory execution and suspicious child processes.
- Network and telemetry: profile normal OneDrive/Outlook behavior and flag anomalous data transfers or atypical file naming patterns used for heartbeat or exfiltration.
- User training and threat-informed exercises: simulate targeted phishing scenarios relevant to policy and government teams, and educate about convincing UI spoofing (like fake attachment previews).
- Incident readiness: maintain playbooks that include checking for deserialization exploitation, analyzing DLL sideloading indicators, and hunting for artifacts associated with Antino’s loader and polling cadence.
Why this campaign matters
Antino illustrates a broader trend: threat actors increasingly exploit legitimate cloud platforms and signed binaries to evade detection, while investing in recon to craft believable lures. For organizations in the campaign’s focus areas — and for any entity relying heavily on Microsoft 365 — the attack underscores the need to combine email hygiene, cloud telemetry monitoring, endpoint protections, and user awareness. Detecting and disrupting such campaigns requires looking beyond simple blocklists to behavioral baselining and rapid response capability.
Breaking the code: how a multi-stage “code of conduct” phishing campaign led to AiTM token compromise
Phishing has evolved from crude scams to carefully engineered deceptions that mimic…
Citrix NetScaler Reboots After Emergency 0-Day Patch: What Teams Need to Know
Citrix released emergency builds to address two actively exploited zero-day vulnerabilities in…
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Microsoft’s SharePoint platform is facing active exploitation following the public release of…
Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor
Akira’s latest tactics expand the ransomware playbook: instead of relying solely on…