New Backdoor Hides C2 Traffic Inside Microsoft 365
Cisco Talos has disclosed a China-nexus espionage campaign deploying a previously undocumented Windows backdoor dubbed Antino, which routes its entire command-and-control channel through legitimate Microsoft Outlook and OneDrive services rather than attacker-owned infrastructure. Talos tracks the activity cluster as UAT-11587, assessed as China-nexus with high confidence, and reports the campaign has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, with secondary targeting observed in Syria.
The operation was first detected in September 2025 against Taiwan's academic, think-tank, and civil-society policy community, with activity escalating sharply between March and June 2026 and peaking in a concentrated wave on June 8–9, 2026 that struck dozens of government IT systems, including roughly 57 newly identified Indian targets. Security researcher Ashley Shen, who authored the Talos writeup, said the campaign has affected at least 16 entities across eight countries, while separate reporting citing the same research puts the total number of compromised endpoints at approximately 350 between September 2025 and July 2026.
Campaign Details
| Attribute | Detail |
|---|---|
| Backdoor | Antino (Rust-compiled, 32-bit and 64-bit Windows variants) |
| Tracked as | UAT-11587 (Cisco Talos designation) |
| Attribution | China-nexus, high confidence |
| First observed | September 2025 (Taiwan) |
| Peak activity | March–June 2026, concentrated wave June 8–9, 2026 |
| Primary targets | Government, defense, diplomatic, legislative, law enforcement, academic, and think-tank organizations |
| Countries affected | Taiwan, India, Philippines, Cambodia, Pakistan, Thailand, Myanmar (plus Syria) |
| C2 channel | Microsoft Graph API — Outlook mailbox + OneDrive |
| Related clusters | Overlaps with Jewelbug; tactical similarities to CL-STA-0049, Earth Alux, Ink Dragon, REF7707 |
Initial Access
UAT-11587 relies on tailored spear-phishing with notably sophisticated social engineering. Talos observed emails that spoofed sender identities to slip past SPF/DMARC checks and embedded a closely replicated reconstruction of Gmail's native attachment-preview widget, built from Base64-encoded PNG images inside HTML, to display a fake attachment card. Clicking the card routes the victim to attacker-controlled Cloudflare Pages links, which deliver HTA or Windows Script Host (WSF) stagers.
Multi-Stage Delivery Chain
- Spear-phishing email with a spoofed sender and a fake Gmail-style attachment card linking to a Cloudflare Pages URL
- HTA/WSF stager executes and downloads a JavaScript downloader/decryptor second stage
- .NET deserialization abuse loads TestAssembly.dll in memory
- The chain opens a lure document and drops a decoy Calculator executable to distract the victim while launching Antino
- Antino loads via DLL sideloading — a malicious
slc.dllpayload is sideloaded through the legitimate, Microsoft-signed binary GatherOsState.exe
Antino also abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through a trusted Windows component, a technique intended to blend malicious execution into routine diagnostic activity.
How the Outlook/OneDrive C2 Works
Antino's defining feature is that it has no traditional C2 server at all. Instead, it authenticates to Microsoft 365 via an Entra ID application using the OAuth 2.0 client-credentials flow, giving it programmatic access to Graph API endpoints without any interactive login:
- OneDrive as a dead drop: the implant uploads heartbeat telemetry roughly every minute, including machine name, username, platform, session identifier, and campaign metadata, and uses OneDrive folders to receive attacker tools and exfiltrate stolen data.
- Outlook as a tasking channel: Antino polls a threat-actor-controlled mailbox every 10 seconds for messages with the subject prefix
command_req_[session_id], executes the embedded instructions, and returns results via matchingcommand_res_[session_id]messages.
Because all of this traffic terminates at graph.microsoft.com and login.microsoftonline.com — domains that virtually every enterprise network already trusts and that are indistinguishable from routine Microsoft 365 sync activity — purely network-based detection is substantially harder than with conventional C2.
Attribution Indicators
Talos assessed the campaign as China-nexus with high confidence based on zh-CN language and Simplified Chinese metadata present in lure documents, UTC+08:00 timezone headers in spear-phishing message headers, and nearly a dozen distinct Antino build artifacts containing Cargo registry paths referencing rsproxy[.]cn, a mainland-China mirror for the Rust crates.io package registry. UAT-11587 shares some infrastructure and tradecraft overlap with the previously documented Jewelbug cluster, but Talos said it could not establish a direct link between this espionage activity and Jewelbug's financially motivated cryptocurrency-fraud operations, and so classified UAT-11587 as a distinct activity set.
Why Outlook/OneDrive C2 Matters
| Impact Area | Description |
|---|---|
| Detection evasion | C2 blends into legitimate Microsoft 365 sync traffic to trusted Microsoft domains, defeating IP/domain-reputation blocking |
| Trust abuse | OAuth client-credentials auth against Entra ID means no interactive sign-in or MFA prompt is ever triggered |
| Scale of compromise | At least 16 government and policy entities across eight Asian countries; estimates of total compromised endpoints run to roughly 350 |
| Sensitive targeting | Victims include defense, diplomatic, legislative, and law-enforcement bodies — high intelligence value for a state-nexus actor |
| Technique reuse risk | Cloud-service C2 (Graph API dead drops) is replicable by other APT and criminal groups once documented, raising future detection burden |
This campaign reflects a broader shift among state-nexus actors toward "living off trusted cloud" tradecraft — abusing SaaS platforms that defenders are reluctant to block outright because doing so disrupts legitimate business operations.
Recommendations
For Security Teams
- Monitor Microsoft Graph API calls for unfamiliar or newly registered Entra ID application service principals, particularly those with OAuth client-credentials grants and Mail.Read/Files.ReadWrite-class permissions they shouldn't need
- Hunt for Outlook mailbox access patterns consistent with automated polling (regular ~10-second intervals) against messages with
command_req_/command_res_subject patterns - Flag OneDrive activity uploading small, frequent (roughly per-minute) files consistent with heartbeat beaconing, and inspect any folder paths resembling
/antino/ - Watch for DLL sideloading involving
GatherOsState.exeand unexpected loading ofTestAssembly.dllorslc.dll - Deploy available Cisco Talos ClamAV signatures and Snort rules for Antino and its delivery chain
For Email and Endpoint Defenders
- Enforce SPF, DKIM, and DMARC to reduce the effectiveness of sender spoofing used in the initial lure
- Treat HTML emails containing embedded Base64-encoded image "attachment previews" (mimicking Gmail's native UI) as a phishing red flag, especially when the underlying link points to Cloudflare Pages
- Block or closely monitor mshta.exe and Windows Script Host (wscript/cscript) execution originating from email-delivered content
- Alert on PowerShell execution invoked through the Windows Scripted Diagnostics framework, an unusual but documented Antino technique
For Government and Policy Organizations in Targeted Regions
- Organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria operating in foreign-affairs, defense, maritime, or diplomatic policy spaces should treat this as an active, targeted threat and conduct proactive threat hunts rather than waiting for alerts
- Review Entra ID application consent grants and audit logs for anomalous API activity tied to this campaign's timeframe (September 2025–present)
- Brief staff handling sensitive policy correspondence on the specific spear-phishing lure style documented by Talos
Key Takeaways
- Antino is a Rust-compiled Windows backdoor attributed to a China-nexus cluster Cisco Talos tracks as UAT-11587, active since at least September 2025.
- Its command-and-control runs entirely through Microsoft 365 — Outlook mailbox polling for tasking, OneDrive for heartbeats and file transfer — authenticated via Entra ID OAuth client-credentials, with no dedicated C2 server.
- Delivery relies on sophisticated spear-phishing featuring a fake Gmail attachment-preview UI, Cloudflare Pages-hosted stagers, and DLL sideloading through the legitimate GatherOsState.exe binary.
- Targets span government, defense, diplomatic, and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria, with at least 16 confirmed entities and estimates of roughly 350 compromised endpoints.
- UAT-11587 overlaps with the previously documented Jewelbug cluster but is tracked separately, as Talos found no link to Jewelbug's financially motivated cryptocurrency activity.
- Defenders should prioritize Entra ID application and Graph API auditing over traditional network-based C2 detection, since Antino's traffic is designed to be indistinguishable from legitimate Microsoft 365 usage.