Hackers Use Microsoft 365 to Control Windows Backdoor
Key Takeaways A new Windows backdoor, dubbed “Antino,” leverages Microsoft 365 services, specifically Outlook and OneDrive, for its entire command-and-control (C2) infrastructure. The...
Key Takeaways
- A new Windows backdoor, dubbed “Antino,” leverages Microsoft 365 services, specifically Outlook and OneDrive, for its entire command-and-control (C2) infrastructure.
- The threat actor, tracked as UAT-11587 and assessed to have ties to China, has targeted government, defense, diplomatic, academic, and policy organizations across eight Asian countries.
- The campaign, active since September 2025, has compromised approximately 350 endpoints by July 2026.
- Initial infection relies on sophisticated spear-phishing emails delivering malicious documents and fake software installers.
- Defenders should implement robust email authentication, user awareness training, and monitor for suspicious activity on Microsoft 365 services and Windows troubleshooting components.
Hackers Built a Windows Backdoor
Cybersecurity researchers have uncovered a sophisticated Windows backdoor, named Antino, that uniquely harnesses Microsoft 365 as its native command and control (C2) platform. This malware leverages common enterprise cloud services like Outlook and OneDrive to transmit commands, exfiltrate sensitive data, and maintain persistent access to compromised systems. The full details of this operation are outlined in a comprehensive report.
Table Of Content
The campaign, identified by Cisco Talos as UAT-11587, commenced in September 2025. Its primary targets include governmental, defense, diplomatic, academic, and policy-focused organizations, predominantly located in Asia. Initial infiltration vectors involve highly customized spear-phishing emails, deceptive documents, and counterfeit software installers. This strategy exploits the inherent trust users place in familiar interfaces and widely adopted cloud services.
By July 2026, Cisco Talos reported that their investigation had revealed approximately 350 compromised endpoints spanning eight countries. These affected nations include Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. The researchers confirmed ten institutional environments as compromised, with another five probable, alongside one identified intended target. Cisco Talos has attributed this operation to a China-nexus threat actor with high confidence, as detailed in a report by Cisco Talos.
These findings underscore a growing trend where adversaries exploit legitimate cloud platforms to circumvent traditional email security measures. Cisco Talos assesses that the primary objective of this particular campaign is intelligence gathering, rather than financial gain.
Antino’s Microsoft 365 C2 Mechanism
Antino is developed in Rust and exists in both executable and library formats. Its C2 functionality is entirely built upon the Microsoft Graph API, which is the programmatic interface for accessing Microsoft’s cloud services. Commands and their corresponding responses are ferried via Outlook messages, while OneDrive is utilized for critical operations such as malware registration, victim status updates, storing exfiltrated files, and staging additional attacker tools.
While the abuse of cloud services for covert communications is not novel, Antino distinguishes itself by integrating its entire native control workflow within the Microsoft 365 ecosystem. Notably, the cloud infrastructure used for the initial delivery of the malware is kept distinct from the Microsoft 365 services that facilitate its post-installation control.
Newer iterations of Antino authenticate through an Entra ID application using pre-configured application credentials, eliminating the need for an interactive user login. The backdoor continuously polls an attacker-controlled Outlook mailbox every ten seconds, extracting commands embedded within message bodies. It then posts responses, enabling operators to correlate task results with specific instructions.
Concurrently, a status file is uploaded to OneDrive every minute, containing vital information such as the compromised computer’s name, username, operating system platform, session identifier, and campaign code. Dedicated folders within OneDrive serve as staging areas for stolen victim files and incoming attacker tools. This intricate system allows threat actors to manage infected machines without exposing a dedicated command-and-control server to network monitoring tools.
The Antino backdoor possesses a range of capabilities, including system enumeration, execution of shell and PowerShell commands, file transfer, program execution, and the ability to load supplementary code directly into memory. An optional obfuscation feature encrypts secondary payloads during periods of inactivity, thereby reducing their susceptibility to memory scanners, though it does not conceal the entire Antino process or guarantee complete evasion.
Phishing Tactics and Infection Chain
The initial compromise phase of the UAT-11587 campaign relies on highly convincing spear-phishing emails. These emails impersonate legitimate organizations and meticulously replicate Gmail’s attachment preview cards. Instead of directly attaching a file, clicking the apparent attachment redirects the victim to an attacker-controlled download link. The emails are carefully crafted with themes relevant to the targets, such as policy events, legislative taxation, maritime disputes, and government administration, to maximize their persuasive power.
In one observed instance, the sender’s domain passed DMARC authentication, yet the visible sender address did not match the authenticated domain. Despite DMARC detecting this discrepancy, a monitoring-only policy allowed the email to be delivered. This highlights a critical point: a successful sender authentication check does not necessarily validate the identity of the organization that recipients believe is contacting them.
The infection chain is a multi-stage process, typically involving five steps. It leverages Windows scripting components, encrypted JavaScript, and unsafe .NET object processing to load a downloader directly into memory. This downloader then displays a decoy document to the victim while simultaneously launching a legitimate, signed Microsoft executable alongside the malicious Antino library. This technique, known as DLL sideloading, allows Antino to execute under the guise of a trusted host process.
Cisco Talos’s attribution to a China-nexus actor is based on various indicators, including language settings within documents, specific development artifacts, and the precise targeting of the campaign. The researchers also noted some overlaps with activity attributed to a group known as Jewelbug, although they could not independently confirm direct links to Jewelbug’s financially motivated operations. Shared delivery infrastructure suggested another potential connection, though this relationship was assessed with low confidence and is being tracked separately.
Antino further abuses legitimate Windows troubleshooting components to execute PowerShell scripts and establish persistence upon system startup. While this method obscures the execution path, it still leaves detectable traces such as script activity, file creation, and registry modifications. The Cisco Talos report provides detailed detection signatures and network rules to aid defenders in identifying and mitigating this threat, along with the following verified indicators of compromise:
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 |
HTA stager, CSIS Indo-Pacific lure |
| SHA-256 | e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf |
HTA stager, Bajo de Masinloc lure |
| SHA-256 | 4d0fdce4c098635fe9b296c3a82c74645f9885eb5e383aa44a0fe7e50da3ca3f |
HTA stager, Taiwan information-warfare workshop lure |
| SHA-256 | f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 |
HTA stager, Taiwan legislative-tax lure |
| SHA-256 | 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a |
HTA stager, Venezuela and Ukraine news lure |
| SHA-256 | 5a35fcd4458e808ab0fa52bb2a92923b60566ee4d7aaadaac7c95cad3d839562 |
HTA stager, Venezuela and Ukraine news lure |
| SHA-256 | 17b53ffa8e005f0e82491d3f9c0a4984c44da52e1668a855c11a137f627c5b4b |
HTA stager, institutional disciplinary-action lure |
| SHA-256 | 484ab497072ea09f12187b349f5b1c80754e4942408a009cccb20a2a3c8c6506 |
WSF stager, institutional disciplinary-action lure |
| SHA-256 | 3a94910eb8022592ce030e6861359f7e980fc1b5a6ccd290cbb071d3e95ed02a |
HTA stager, TPiE inauguration lure |
| SHA-256 | 6a1dbbfcfe6867ac83d35012b2717084388b4a34707efd0b725466dfd0e8fa56 |
WSF stager, TPiE inauguration lure |
| SHA-256 | 75c12795016ae48b1bddd34a9f5adea63a12f58701eae01e1b4ab3d9dfa1513c |
HTA stager, Tehran bilateral-summit lure |
| SHA-256 | bd8ddc8f33e0fe43147ee6f1713654996420a27c5d2cd91751ad67124ebc6fe4 |
WSF stager, Tehran bilateral-summit lure |
| SHA-256 | b75492466462141c56d97b705f0c606faf272577631dc2822aa8d6bda53633b6 |
HTA stager, cross-border repression seminar lure |
| SHA-256 | 23d5f1af8581ae200615d9a66d539f2043c3248b649e862557b379d7e8b7a3ac |
WSF stager, cross-border repression seminar lure |
| SHA-256 | 0b4e5e017c0f0ccac79e13ca5d580a75af67a24ca0763f9ebfdaaeb1ba4fc739 |
HTA stager, Latin carnival lure |
| SHA-256 | ae1b45fb56b9f1b9cb3ee30d2bb1279c9b90b70bb62f8de305d198c6a4e0585e |
WSF stager, Latin carnival lure |
| SHA-256 | cd3509fa82e506cc6f2eeafa0a45d4b8b76a07edadd29779daf00568febcaba7 |
HTA stager, C-DAC lure |
| SHA-256 | b8e6e83a73e6e07f8873c364dd2a4b830bceb60758163e2efcd7e387cb604655 |
WSF stager, C-DAC lure |
| SHA-256 | 7969ae5f11fc163049c8eadba06f814f5edece13a707e6087c1c49011a45b838 |
HTA stager, Latin carnival lure variant |
| SHA-256 | aea5e9029f9212d05bde10f7806d1f2819be45d167e6fd877b9fb1b11088ac90 |
WSF stager, Latin carnival lure variant |
| SHA-256 | 7fa98efba59614cec0b7291aedee98764f8dc037b6cc798c93951a31208e9e32 |
HTA stager, internal-review lure |
| SHA-256 | 65f4b9292e91abfa5adf42a03526932930c1c0a436bb186a7948fe6770295788 |
WSF stager, internal-review lure |
| SHA-256 | 61a8f5add6c35f99c389012dbb2343061fd0b54611b40490b9a7f0b49d707da0 |
Stage 2 JScript downloader and decryptor |
| SHA-256 | 747b1d13bdf06956b5da5f47250fefd5284ebcf7961971732c3d348aa1a2d533 |
Stage 2 JScript downloader and decryptor |
| SHA-256 | a13182699a12a8dd9d07c336dbd8de5e9b086b9b09793b7de2e9761aa03ce1dc |
Stage 2 JScript downloader and decryptor |
| SHA-256 | 2f1513c822af0c6635dd3c69dc38f0b2f6e02012ea36415fff111a5d4d5fae05 |
Stage 2 JScript downloader and decryptor |
| SHA-256 | a0e91085f08956a9a7034ace73cee60cb211f5d96f02bc91a026601bde8f2221 |
Stage 2 downloader, HTA branch |
| SHA-256 | 47f98dfe01759a464e22d5ec55d012dccb38ce010dd73e3ba8d7ffefca12b4b2 |
Stage 2 downloader, WSF branch |
| SHA-256 | b3416726a064dd7f657bbb400adeb365eea7f8bb60783ad2d9da1a1d93768731 |
Stage 2 downloader, HTA branch |
| SHA-256 | 0a6fb71ab1362d065c7ec2678c1e73d9a0721b0e7099d392ba7559bb2eec4970 |
Stage 2 downloader, WSF branch |
| SHA-256 | f0c1dc6d6daa4d010932c7818ed5f22929c182f58e5f495fabe2fb3cfc835b97 |
Encrypted JScript orchestrator |
| SHA-256 | 5555e904101689351a2a1359c9c06da0a57139a9470df7d26823c1b75db55041 |
Encrypted BinaryFormatter resource |
| SHA-256 | 5168a2696a0ed858f996f388bfe94f952d475158f4ee6206816608936db005ca |
Encrypted BinaryFormatter resource |
| SHA-256 | 7c2ac9c040b3300bffa7d2e435dbb1bc12e7efd644d2216d603c72121266395c |
Encrypted JScript orchestrator |
| SHA-256 | d87201c1299a7f5854929645e6891c6c424d2a690031272bedacba7c5fe73a3e |
Encrypted BinaryFormatter resource |
| SHA-256 | 334f39279ff3aae40fe74340c887ae018c75bc42790586bdf9070adb5889100c |
Encrypted BinaryFormatter resource |
| SHA-256 | 077bd873217d8abfbb6482d11966ca34f3fef7ad5166f24fbc5dc3ddefe894a1 |
Encrypted JScript orchestrator |
| SHA-256 | ad0bd2b45e2416fb1384bf30af068d857e7c06b4226615d66b55b610a34c5670 |
Encrypted BinaryFormatter resource |
| SHA-256 | e2f59d8d5a81583ed482b6c7bf37699efdb2264e452cf7d8cfc0c54dfbd9ab3f |
Encrypted BinaryFormatter resource |
| SHA-256 | 3a4c9020eeb5ef22a1ff443e606ccb6705fe287c583121c713d2c9f9f1f2a2af |
Encrypted JScript orchestrator |
| SHA-256 | 4b614e5c37abaddca162119e42a969945caa681305e246e0ed0060ea9984008b |
Encrypted JScript orchestrator |
| SHA-256 | c8e1239d7276178b6620f47ec4880494be1cb394477b223fc54bffb0947bff50 |
Encrypted BinaryFormatter resource |
| SHA-256 | 079acd58a74479ac8b108b618d2a4da8a8bd560a04459cd90e2fec9da5027513 |
Encrypted BinaryFormatter resource |
| SHA-256 | 8e1d68906d6de92f359945d3a95da1480e72773a3e8dea7682d6bf0f6699f75f |
Encrypted JScript orchestrator |
| SHA-256 | 170b0eee60a335f32c1d0c19a0bb8d8bbc0a5b298ea9486b546f58d25cc8a464 |
Encrypted BinaryFormatter resource |
| SHA-256 | b31ca75f73a9363b0e35042a41216c3f581eaa0b9cd78cb58f089c2e40babd40 |
Encrypted BinaryFormatter resource |
| SHA-256 | d753a615aedf8e58ffc75b2b7ebd320c0cbe6bcb5cbb885db749a2a85c55d3bf |
TestAssembly.dll downloader |
| SHA-256 | 133a46ba41136ca21c93fb08c28446826d8c0d9b7923a16f2d152d595a710098 |
TestAssembly.dll downloader |
| SHA-256 | 9fc50cf28f86201fda8306926817b1ede41fdd993202515905dd072f6803542f |
TestAssembly.dll downloader |
| SHA-256 | d4cb2f5df16ec9b9c5b796ae55848534e15d4f8b8806f0431108fc7a99a2548a |
TestAssembly.dll downloader |
| SHA-256 | 131ac3e0df777910e0a32e43d5744bccb0490750d4c2adc359da41d76d383c46 |
TestAssembly.dll downloader |
| SHA-256 | 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff |
Antino Gen 2 slc.dll backdoor |
| SHA-256 | 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd |
Antino Gen 2 standalone fake installer |
| SHA-256 | 1fadc90b61ce536abda78eb387a7f3d745f00c16775d3f762845ccc0fde567da |
Antino Gen 1 slc.dll backdoor |
| SHA-256 | 40e7e77aff603f4c2ef17b3bc8ea836e714d0734a1e5b946e52f95536ec5c91d |
Configured Antino Gen 1 standalone backdoor |
| SHA-256 | 5c5c060b272cd4a5c3767edc0e9478bd35b7e1756e183d0446a5491bd65519cb |
Configured Antino standalone backdoor |
| SHA-256 | 971cb2448b5d67dcc1f5eaa10d12e77f213035ad31230dc2ac7a510610a2059d |
Antino Gen 2 standalone fake installer |
| SHA-256 | 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 |
Antino Gen 2 standalone fake installer |
| SHA-256 | b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e |
Antino Gen 2 standalone fake installer |
| SHA-256 | ca14ad0344dc7216f6da29a5cbe4237d886cc5257e8c3a48fb4885a311c9b800 |
Unpacked Antino standalone backdoor memory image |
| SHA-256 | e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 |
Antino Gen 2 slc.dll backdoor |
| SHA-256 | e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb |
Antino Gen 2 slc.dll backdoor |
| SHA-256 | fdbd047031c13a17c9f491c9355f44d587584ebe2b8927be8482e6c236c8e1c1 |
Antino Gen 2 slc.dll backdoor |
| IP address | 103[.]27[.]110[.]220 |
Historical serving IP for the payload hosted on wps-cn[.]com |
| Domain | osc-cdn[.]com |
Spear-phishing sender domain |
| Domain | oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev |
Execution-tracking domain |
| Domain | d2nq35tel3ucuo[.]cloudfront[.]net |
CloudFront staging domain |
| Domain | pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev |
Cloudflare R2 staging domain |
| Domain | pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev |
Cloudflare R2 staging domain |
| Domain | my-3lyt6wcp[.]pages[.]dev |
Cloudflare Pages delivery domain |
| Domain | my-qc39r814[.]pages[.]dev |
Cloudflare Pages delivery domain |
| Domain | my-662ylt3w[.]pages[.]dev |
Cloudflare Pages delivery domain |
| Domain | my-6g16qsfe[.]pages[.]dev |
Cloudflare Pages delivery domain |
| Domain | my-goq6xmbm[.]pages[.]dev |
Cloudflare Pages delivery domain |
| Domain | my-h3qli6kq[.]pages[.]dev |
Cloudflare Pages delivery domain |
| Domain | my-sv7c1fzs[.]pages[.]dev |
Cloudflare Pages delivery domain |
| Domain | my-u0up9qri[.]pages[.]dev |
Cloudflare Pages delivery domain |
| Domain | my-vtsdod2n[.]pages[.]dev |
Cloudflare Pages delivery domain |
| Domain | my-wgoxp32b[.]pages[.]dev |
Cloudflare Pages delivery domain |
| Domain | microsoft-flash[.]com |
Standalone fake-installer delivery domain |
| Domain | wps-cn[.]com |
Standalone fake-installer delivery domain |
| URL | hxxps://microsoft-flash[.]com/download/flashcenter_pp_ax_install_en.exe |
Standalone Antino fake-installer delivery |
| URL | hxxps://www[.]wps-cn[.]com/downloads/flashcenter_pp_ax_install_en.exe |
Standalone Antino fake-installer delivery |
| URL | hxxps://my-662ylt3w[.]pages[.]dev/Institutional_Disciplinary_Action_Report_May_2026.hta |
HTA delivery |
| URL | hxxps://my-662ylt3w[.]pages[.]dev/Institutional_Disciplinary_Action_Report_May_2026.wsf |
WSF delivery |
| URL | hxxps://my-6g16qsfe[.]pages[.]dev/the%20May%2027%20inauguration%20of%20the%20TPiE.hta |
HTA delivery |
| URL | hxxps://my-6g16qsfe[.]pages[.]dev/the%20May%2027%20inauguration%20of%20the%20TPiE.wsf |
WSF delivery |
| URL | hxxps://my-goq6xmbm[.]pages[.]dev/Tehran_Bilateral_Summit_Proceedings_May2026.hta |
HTA delivery |
| URL | hxxps://my-goq6xmbm[.]pages[.]dev/Tehran_Bilateral_Summit_Proceedings_May2026.wsf |
WSF delivery |
| URL | hxxps://my-h3qli6kq[.]pages[.]dev/CrossBorder_Repression_Seminar_Agenda.hta |
HTA delivery |
| URL | hxxps://my-h3qli6kq[.]pages[.]dev/CrossBorder_Repression_Seminar_Agenda.wsf |
WSF delivery |
| URL | hxxps://my-sv7c1fzs[.]pages[.]dev/Extravaganza%20Latin%20Carnival.hta |
HTA delivery |
| URL | hxxps://my-sv7c1fzs[.]pages[.]dev/Extravaganza%20Latin%20Carnival.wsf |
WSF delivery |
| URL | hxxps://my-u0up9qri[.]pages[.]dev/UO%20-C-DAC%20%281%29.hta |
HTA delivery |
| URL | hxxps://my-u0up9qri[.]pages[.]dev/UO%20-C-DAC%20%281%29.wsf |
WSF delivery |
| URL | hxxps://my-vtsdod2n[.]pages[.]dev/Extravaganza%20Latin%20Carnival%20post%20copy.hta |
HTA delivery |
| URL | hxxps://my-vtsdod2n[.]pages[.]dev/Extravaganza%20Latin%20Carnival%20post%20copy.wsf |
WSF delivery |
| URL | hxxps://my-wgoxp32b[.]pages[.]dev/Internal_Review_Dossier_0520.hta |
HTA delivery |
| URL | hxxps://my-wgoxp32b[.]pages[.]dev/Internal_Review_Dossier_0520.wsf |
WSF delivery |
| URL | hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/4oyE4n4ozLQ0.log |
Stage 2 delivery |
| URL | hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/LtVGUSsyUTDA.log |
Stage 2 delivery |
| URL | hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/TzzyYlYnJ40Z.log |
Stage 2 delivery |
| URL | hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/tdyvHHVcr
|



No Comment! Be the first one.