Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Hackers Use Microsoft 365 to Control Windows Backdoor
October 1, 2026
Alleged KillSec Ransomware Group Leader Arrested, Servers Dismantled
October 1, 2026
Fake Zoom Installer Delivers CloudSyncD Backdoor to macOS Users
October 1, 2026
Home/Threats/Hackers Use Microsoft 365 to Control Windows Backdoor
Threats

Hackers Use Microsoft 365 to Control Windows Backdoor

Key Takeaways A new Windows backdoor, dubbed “Antino,” leverages Microsoft 365 services, specifically Outlook and OneDrive, for its entire command-and-control (C2) infrastructure. The...

Emy Elsamnoudy
Emy Elsamnoudy
October 1, 2026 6 Min Read
4 0

Key Takeaways

  • A new Windows backdoor, dubbed “Antino,” leverages Microsoft 365 services, specifically Outlook and OneDrive, for its entire command-and-control (C2) infrastructure.
  • The threat actor, tracked as UAT-11587 and assessed to have ties to China, has targeted government, defense, diplomatic, academic, and policy organizations across eight Asian countries.
  • The campaign, active since September 2025, has compromised approximately 350 endpoints by July 2026.
  • Initial infection relies on sophisticated spear-phishing emails delivering malicious documents and fake software installers.
  • Defenders should implement robust email authentication, user awareness training, and monitor for suspicious activity on Microsoft 365 services and Windows troubleshooting components.

Hackers Built a Windows Backdoor

Cybersecurity researchers have uncovered a sophisticated Windows backdoor, named Antino, that uniquely harnesses Microsoft 365 as its native command and control (C2) platform. This malware leverages common enterprise cloud services like Outlook and OneDrive to transmit commands, exfiltrate sensitive data, and maintain persistent access to compromised systems. The full details of this operation are outlined in a comprehensive report.

Table Of Content

  • Key Takeaways
  • Hackers Built a Windows Backdoor
  • Antino’s Microsoft 365 C2 Mechanism
  • Phishing Tactics and Infection Chain

The campaign, identified by Cisco Talos as UAT-11587, commenced in September 2025. Its primary targets include governmental, defense, diplomatic, academic, and policy-focused organizations, predominantly located in Asia. Initial infiltration vectors involve highly customized spear-phishing emails, deceptive documents, and counterfeit software installers. This strategy exploits the inherent trust users place in familiar interfaces and widely adopted cloud services.

By July 2026, Cisco Talos reported that their investigation had revealed approximately 350 compromised endpoints spanning eight countries. These affected nations include Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. The researchers confirmed ten institutional environments as compromised, with another five probable, alongside one identified intended target. Cisco Talos has attributed this operation to a China-nexus threat actor with high confidence, as detailed in a report by Cisco Talos.

These findings underscore a growing trend where adversaries exploit legitimate cloud platforms to circumvent traditional email security measures. Cisco Talos assesses that the primary objective of this particular campaign is intelligence gathering, rather than financial gain.

Antino’s Microsoft 365 C2 Mechanism

Antino is developed in Rust and exists in both executable and library formats. Its C2 functionality is entirely built upon the Microsoft Graph API, which is the programmatic interface for accessing Microsoft’s cloud services. Commands and their corresponding responses are ferried via Outlook messages, while OneDrive is utilized for critical operations such as malware registration, victim status updates, storing exfiltrated files, and staging additional attacker tools.

While the abuse of cloud services for covert communications is not novel, Antino distinguishes itself by integrating its entire native control workflow within the Microsoft 365 ecosystem. Notably, the cloud infrastructure used for the initial delivery of the malware is kept distinct from the Microsoft 365 services that facilitate its post-installation control.

Newer iterations of Antino authenticate through an Entra ID application using pre-configured application credentials, eliminating the need for an interactive user login. The backdoor continuously polls an attacker-controlled Outlook mailbox every ten seconds, extracting commands embedded within message bodies. It then posts responses, enabling operators to correlate task results with specific instructions.

Concurrently, a status file is uploaded to OneDrive every minute, containing vital information such as the compromised computer’s name, username, operating system platform, session identifier, and campaign code. Dedicated folders within OneDrive serve as staging areas for stolen victim files and incoming attacker tools. This intricate system allows threat actors to manage infected machines without exposing a dedicated command-and-control server to network monitoring tools.

The Antino backdoor possesses a range of capabilities, including system enumeration, execution of shell and PowerShell commands, file transfer, program execution, and the ability to load supplementary code directly into memory. An optional obfuscation feature encrypts secondary payloads during periods of inactivity, thereby reducing their susceptibility to memory scanners, though it does not conceal the entire Antino process or guarantee complete evasion.

Phishing Tactics and Infection Chain

The initial compromise phase of the UAT-11587 campaign relies on highly convincing spear-phishing emails. These emails impersonate legitimate organizations and meticulously replicate Gmail’s attachment preview cards. Instead of directly attaching a file, clicking the apparent attachment redirects the victim to an attacker-controlled download link. The emails are carefully crafted with themes relevant to the targets, such as policy events, legislative taxation, maritime disputes, and government administration, to maximize their persuasive power.

In one observed instance, the sender’s domain passed DMARC authentication, yet the visible sender address did not match the authenticated domain. Despite DMARC detecting this discrepancy, a monitoring-only policy allowed the email to be delivered. This highlights a critical point: a successful sender authentication check does not necessarily validate the identity of the organization that recipients believe is contacting them.

The infection chain is a multi-stage process, typically involving five steps. It leverages Windows scripting components, encrypted JavaScript, and unsafe .NET object processing to load a downloader directly into memory. This downloader then displays a decoy document to the victim while simultaneously launching a legitimate, signed Microsoft executable alongside the malicious Antino library. This technique, known as DLL sideloading, allows Antino to execute under the guise of a trusted host process.

Cisco Talos’s attribution to a China-nexus actor is based on various indicators, including language settings within documents, specific development artifacts, and the precise targeting of the campaign. The researchers also noted some overlaps with activity attributed to a group known as Jewelbug, although they could not independently confirm direct links to Jewelbug’s financially motivated operations. Shared delivery infrastructure suggested another potential connection, though this relationship was assessed with low confidence and is being tracked separately.

Antino further abuses legitimate Windows troubleshooting components to execute PowerShell scripts and establish persistence upon system startup. While this method obscures the execution path, it still leaves detectable traces such as script activity, file creation, and registry modifications. The Cisco Talos report provides detailed detection signatures and network rules to aid defenders in identifying and mitigating this threat, along with the following verified indicators of compromise:

Type Indicator Description
SHA-256 e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 HTA stager, CSIS Indo-Pacific lure
SHA-256 e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf HTA stager, Bajo de Masinloc lure
SHA-256 4d0fdce4c098635fe9b296c3a82c74645f9885eb5e383aa44a0fe7e50da3ca3f HTA stager, Taiwan information-warfare workshop lure
SHA-256 f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 HTA stager, Taiwan legislative-tax lure
SHA-256 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a HTA stager, Venezuela and Ukraine news lure
SHA-256 5a35fcd4458e808ab0fa52bb2a92923b60566ee4d7aaadaac7c95cad3d839562 HTA stager, Venezuela and Ukraine news lure
SHA-256 17b53ffa8e005f0e82491d3f9c0a4984c44da52e1668a855c11a137f627c5b4b HTA stager, institutional disciplinary-action lure
SHA-256 484ab497072ea09f12187b349f5b1c80754e4942408a009cccb20a2a3c8c6506 WSF stager, institutional disciplinary-action lure
SHA-256 3a94910eb8022592ce030e6861359f7e980fc1b5a6ccd290cbb071d3e95ed02a HTA stager, TPiE inauguration lure
SHA-256 6a1dbbfcfe6867ac83d35012b2717084388b4a34707efd0b725466dfd0e8fa56 WSF stager, TPiE inauguration lure
SHA-256 75c12795016ae48b1bddd34a9f5adea63a12f58701eae01e1b4ab3d9dfa1513c HTA stager, Tehran bilateral-summit lure
SHA-256 bd8ddc8f33e0fe43147ee6f1713654996420a27c5d2cd91751ad67124ebc6fe4 WSF stager, Tehran bilateral-summit lure
SHA-256 b75492466462141c56d97b705f0c606faf272577631dc2822aa8d6bda53633b6 HTA stager, cross-border repression seminar lure
SHA-256 23d5f1af8581ae200615d9a66d539f2043c3248b649e862557b379d7e8b7a3ac WSF stager, cross-border repression seminar lure
SHA-256 0b4e5e017c0f0ccac79e13ca5d580a75af67a24ca0763f9ebfdaaeb1ba4fc739 HTA stager, Latin carnival lure
SHA-256 ae1b45fb56b9f1b9cb3ee30d2bb1279c9b90b70bb62f8de305d198c6a4e0585e WSF stager, Latin carnival lure
SHA-256 cd3509fa82e506cc6f2eeafa0a45d4b8b76a07edadd29779daf00568febcaba7 HTA stager, C-DAC lure
SHA-256 b8e6e83a73e6e07f8873c364dd2a4b830bceb60758163e2efcd7e387cb604655 WSF stager, C-DAC lure
SHA-256 7969ae5f11fc163049c8eadba06f814f5edece13a707e6087c1c49011a45b838 HTA stager, Latin carnival lure variant
SHA-256 aea5e9029f9212d05bde10f7806d1f2819be45d167e6fd877b9fb1b11088ac90 WSF stager, Latin carnival lure variant
SHA-256 7fa98efba59614cec0b7291aedee98764f8dc037b6cc798c93951a31208e9e32 HTA stager, internal-review lure
SHA-256 65f4b9292e91abfa5adf42a03526932930c1c0a436bb186a7948fe6770295788 WSF stager, internal-review lure
SHA-256 61a8f5add6c35f99c389012dbb2343061fd0b54611b40490b9a7f0b49d707da0 Stage 2 JScript downloader and decryptor
SHA-256 747b1d13bdf06956b5da5f47250fefd5284ebcf7961971732c3d348aa1a2d533 Stage 2 JScript downloader and decryptor
SHA-256 a13182699a12a8dd9d07c336dbd8de5e9b086b9b09793b7de2e9761aa03ce1dc Stage 2 JScript downloader and decryptor
SHA-256 2f1513c822af0c6635dd3c69dc38f0b2f6e02012ea36415fff111a5d4d5fae05 Stage 2 JScript downloader and decryptor
SHA-256 a0e91085f08956a9a7034ace73cee60cb211f5d96f02bc91a026601bde8f2221 Stage 2 downloader, HTA branch
SHA-256 47f98dfe01759a464e22d5ec55d012dccb38ce010dd73e3ba8d7ffefca12b4b2 Stage 2 downloader, WSF branch
SHA-256 b3416726a064dd7f657bbb400adeb365eea7f8bb60783ad2d9da1a1d93768731 Stage 2 downloader, HTA branch
SHA-256 0a6fb71ab1362d065c7ec2678c1e73d9a0721b0e7099d392ba7559bb2eec4970 Stage 2 downloader, WSF branch
SHA-256 f0c1dc6d6daa4d010932c7818ed5f22929c182f58e5f495fabe2fb3cfc835b97 Encrypted JScript orchestrator
SHA-256 5555e904101689351a2a1359c9c06da0a57139a9470df7d26823c1b75db55041 Encrypted BinaryFormatter resource
SHA-256 5168a2696a0ed858f996f388bfe94f952d475158f4ee6206816608936db005ca Encrypted BinaryFormatter resource
SHA-256 7c2ac9c040b3300bffa7d2e435dbb1bc12e7efd644d2216d603c72121266395c Encrypted JScript orchestrator
SHA-256 d87201c1299a7f5854929645e6891c6c424d2a690031272bedacba7c5fe73a3e Encrypted BinaryFormatter resource
SHA-256 334f39279ff3aae40fe74340c887ae018c75bc42790586bdf9070adb5889100c Encrypted BinaryFormatter resource
SHA-256 077bd873217d8abfbb6482d11966ca34f3fef7ad5166f24fbc5dc3ddefe894a1 Encrypted JScript orchestrator
SHA-256 ad0bd2b45e2416fb1384bf30af068d857e7c06b4226615d66b55b610a34c5670 Encrypted BinaryFormatter resource
SHA-256 e2f59d8d5a81583ed482b6c7bf37699efdb2264e452cf7d8cfc0c54dfbd9ab3f Encrypted BinaryFormatter resource
SHA-256 3a4c9020eeb5ef22a1ff443e606ccb6705fe287c583121c713d2c9f9f1f2a2af Encrypted JScript orchestrator
SHA-256 4b614e5c37abaddca162119e42a969945caa681305e246e0ed0060ea9984008b Encrypted JScript orchestrator
SHA-256 c8e1239d7276178b6620f47ec4880494be1cb394477b223fc54bffb0947bff50 Encrypted BinaryFormatter resource
SHA-256 079acd58a74479ac8b108b618d2a4da8a8bd560a04459cd90e2fec9da5027513 Encrypted BinaryFormatter resource
SHA-256 8e1d68906d6de92f359945d3a95da1480e72773a3e8dea7682d6bf0f6699f75f Encrypted JScript orchestrator
SHA-256 170b0eee60a335f32c1d0c19a0bb8d8bbc0a5b298ea9486b546f58d25cc8a464 Encrypted BinaryFormatter resource
SHA-256 b31ca75f73a9363b0e35042a41216c3f581eaa0b9cd78cb58f089c2e40babd40 Encrypted BinaryFormatter resource
SHA-256 d753a615aedf8e58ffc75b2b7ebd320c0cbe6bcb5cbb885db749a2a85c55d3bf TestAssembly.dll downloader
SHA-256 133a46ba41136ca21c93fb08c28446826d8c0d9b7923a16f2d152d595a710098 TestAssembly.dll downloader
SHA-256 9fc50cf28f86201fda8306926817b1ede41fdd993202515905dd072f6803542f TestAssembly.dll downloader
SHA-256 d4cb2f5df16ec9b9c5b796ae55848534e15d4f8b8806f0431108fc7a99a2548a TestAssembly.dll downloader
SHA-256 131ac3e0df777910e0a32e43d5744bccb0490750d4c2adc359da41d76d383c46 TestAssembly.dll downloader
SHA-256 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff Antino Gen 2 slc.dll backdoor
SHA-256 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd Antino Gen 2 standalone fake installer
SHA-256 1fadc90b61ce536abda78eb387a7f3d745f00c16775d3f762845ccc0fde567da Antino Gen 1 slc.dll backdoor
SHA-256 40e7e77aff603f4c2ef17b3bc8ea836e714d0734a1e5b946e52f95536ec5c91d Configured Antino Gen 1 standalone backdoor
SHA-256 5c5c060b272cd4a5c3767edc0e9478bd35b7e1756e183d0446a5491bd65519cb Configured Antino standalone backdoor
SHA-256 971cb2448b5d67dcc1f5eaa10d12e77f213035ad31230dc2ac7a510610a2059d Antino Gen 2 standalone fake installer
SHA-256 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 Antino Gen 2 standalone fake installer
SHA-256 b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e Antino Gen 2 standalone fake installer
SHA-256 ca14ad0344dc7216f6da29a5cbe4237d886cc5257e8c3a48fb4885a311c9b800 Unpacked Antino standalone backdoor memory image
SHA-256 e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 Antino Gen 2 slc.dll backdoor
SHA-256 e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb Antino Gen 2 slc.dll backdoor
SHA-256 fdbd047031c13a17c9f491c9355f44d587584ebe2b8927be8482e6c236c8e1c1 Antino Gen 2 slc.dll backdoor
IP address 103[.]27[.]110[.]220 Historical serving IP for the payload hosted on wps-cn[.]com
Domain osc-cdn[.]com Spear-phishing sender domain
Domain oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev Execution-tracking domain
Domain d2nq35tel3ucuo[.]cloudfront[.]net CloudFront staging domain
Domain pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev Cloudflare R2 staging domain
Domain pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev Cloudflare R2 staging domain
Domain my-3lyt6wcp[.]pages[.]dev Cloudflare Pages delivery domain
Domain my-qc39r814[.]pages[.]dev Cloudflare Pages delivery domain
Domain my-662ylt3w[.]pages[.]dev Cloudflare Pages delivery domain
Domain my-6g16qsfe[.]pages[.]dev Cloudflare Pages delivery domain
Domain my-goq6xmbm[.]pages[.]dev Cloudflare Pages delivery domain
Domain my-h3qli6kq[.]pages[.]dev Cloudflare Pages delivery domain
Domain my-sv7c1fzs[.]pages[.]dev Cloudflare Pages delivery domain
Domain my-u0up9qri[.]pages[.]dev Cloudflare Pages delivery domain
Domain my-vtsdod2n[.]pages[.]dev Cloudflare Pages delivery domain
Domain my-wgoxp32b[.]pages[.]dev Cloudflare Pages delivery domain
Domain microsoft-flash[.]com Standalone fake-installer delivery domain
Domain wps-cn[.]com Standalone fake-installer delivery domain
URL hxxps://microsoft-flash[.]com/download/flashcenter_pp_ax_install_en.exe Standalone Antino fake-installer delivery
URL hxxps://www[.]wps-cn[.]com/downloads/flashcenter_pp_ax_install_en.exe Standalone Antino fake-installer delivery
URL hxxps://my-662ylt3w[.]pages[.]dev/Institutional_Disciplinary_Action_Report_May_2026.hta HTA delivery
URL hxxps://my-662ylt3w[.]pages[.]dev/Institutional_Disciplinary_Action_Report_May_2026.wsf WSF delivery
URL hxxps://my-6g16qsfe[.]pages[.]dev/the%20May%2027%20inauguration%20of%20the%20TPiE.hta HTA delivery
URL hxxps://my-6g16qsfe[.]pages[.]dev/the%20May%2027%20inauguration%20of%20the%20TPiE.wsf WSF delivery
URL hxxps://my-goq6xmbm[.]pages[.]dev/Tehran_Bilateral_Summit_Proceedings_May2026.hta HTA delivery
URL hxxps://my-goq6xmbm[.]pages[.]dev/Tehran_Bilateral_Summit_Proceedings_May2026.wsf WSF delivery
URL hxxps://my-h3qli6kq[.]pages[.]dev/CrossBorder_Repression_Seminar_Agenda.hta HTA delivery
URL hxxps://my-h3qli6kq[.]pages[.]dev/CrossBorder_Repression_Seminar_Agenda.wsf WSF delivery
URL hxxps://my-sv7c1fzs[.]pages[.]dev/Extravaganza%20Latin%20Carnival.hta HTA delivery
URL hxxps://my-sv7c1fzs[.]pages[.]dev/Extravaganza%20Latin%20Carnival.wsf WSF delivery
URL hxxps://my-u0up9qri[.]pages[.]dev/UO%20-C-DAC%20%281%29.hta HTA delivery
URL hxxps://my-u0up9qri[.]pages[.]dev/UO%20-C-DAC%20%281%29.wsf WSF delivery
URL hxxps://my-vtsdod2n[.]pages[.]dev/Extravaganza%20Latin%20Carnival%20post%20copy.hta HTA delivery
URL hxxps://my-vtsdod2n[.]pages[.]dev/Extravaganza%20Latin%20Carnival%20post%20copy.wsf WSF delivery
URL hxxps://my-wgoxp32b[.]pages[.]dev/Internal_Review_Dossier_0520.hta HTA delivery
URL hxxps://my-wgoxp32b[.]pages[.]dev/Internal_Review_Dossier_0520.wsf WSF delivery
URL hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/4oyE4n4ozLQ0.log Stage 2 delivery
URL hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/LtVGUSsyUTDA.log Stage 2 delivery
URL hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/TzzyYlYnJ40Z.log Stage 2 delivery
URL hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/tdyvHHVcr

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Alleged KillSec Ransomware Group Leader Arrested, Servers Dismantled

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
WordPress Malware Returns With Self-Healing Backdoor
October 1, 2026
Warlock Ransomware Exploits Critical SharePoint Flaws in Water, Telecom Attacks
October 1, 2026
Critical Axios HTTP/2 Vulnerabilities Allow SSRF and DoS Attacks
October 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us