Yaamlabs

Threat intel

Antino backdoor hides its command channel in Microsoft 365

UAT-11587's Antino backdoor takes orders through Outlook and OneDrive via Microsoft Graph. How it works, who was hit, and how to hunt for it.

Cisco Talos published research on September 30 on UAT-11587, a China-nexus espionage group that compromised about 350 Windows endpoints in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria between September 2025 and July 2026. The victims are government, defense, diplomatic, academic and policy organizations: Talos counts 10 confirmed and five probable victim environments, plus one more intended target. The largest single wave came on June 8 and 9, when about 57 new India-linked endpoints appeared.

The group's backdoor, Antino, has no command server of its own. It signs in to Microsoft Graph, the API behind Microsoft 365, and reads its orders from an Outlook mailbox and moves files through OneDrive, both owned by the operator. To a firewall or proxy that traffic looks like any other Microsoft 365 traffic, which is why blocklists and domain reputation miss it. If you run Windows endpoints for a public body, a think tank or a university in the region, hunt for it now. Everyone else should check whether they could even tell which processes on their endpoints talk to Graph.

How it works

The intrusion starts with email. The group sent spear-phishing mail through the Migadu mail service with its own domain, osc-cdn[.]com, as the SMTP envelope sender, while the visible From line showed a trusted organization. DMARC flagged the mismatch, but Talos says the target domain's DMARC policy was p=none, which only reports failures and never blocks them, so the mail was delivered. Inside the message, the "attachment" was a copy of Gmail's attachment preview card built from an embedded image and wrapped in a link to a Cloudflare Pages site.

Clicking it launches a chain that stays inside trusted tooling. An HTA or WSF script runs through mshta.exe and pulls encoded JScript from Cloudflare R2 or Amazon CloudFront. That stage abuses .NET BinaryFormatter deserialization (feeding the runtime a crafted serialized object that turns into running code) to load a loader called TestAssembly.dll into mshta.exe. The loader stages a bundle that includes GatherOsState.exe, a legitimate Microsoft-signed tool from the Windows Assessment and Deployment Kit (ADK). Windows loads DLLs from the program's own folder first, so when GatherOsState.exe starts it loads the attacker's slc.dll from the same folder. That DLL is Antino, written in Rust.

Antino then authenticates to Entra ID as an application using the OAuth 2.0 client-credentials flow. In that flow a program swaps an app ID and secret for an access token at login.microsoftonline.com, with no user, password or MFA prompt involved. With the token it calls Microsoft Graph. It checks the operator's Outlook mailbox every 10 seconds for messages named command_req_[session_id] and replies with command_res_[session_id]. It uploads a heartbeat with the machine name, username, platform and campaign code to /antino/heartbeats/ in OneDrive about once a minute, sends stolen files to /antino_downloads/ and fetches tools from /antino_uploads/.

The app, mailbox and OneDrive all sit in the attacker's own tenant, not yours. Your Entra sign-in logs and Microsoft Graph activity logs record activity against your tenant, so this traffic never appears in them. The only places it shows up are the endpoint and the network path to Microsoft.

What attackers are doing

Antino gives the operator a full remote shell. Its commands run cmd.exe and PowerShell, list directories, collect system details, run programs, move files in both directions and load shellcode in memory, with an optional sleep mask that encrypts the payload while it waits. Some builds can persist through a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

Talos describes two generations of the implant that differ mainly in how they register and send heartbeats; the OneDrive heartbeat files belong to the later one. The China-nexus label rests partly on the build environment: the Rust code was compiled with packages from rsproxy.cn, a mirror aimed at developers in mainland China. The target list, government and policy bodies across Asia, points the same way.

What to do

1. Deploy the published detections

Talos released Snort rules 66880, 66881 and 66882 and a set of ClamAV signatures for the HTML lures and Windows payloads. Load them on your IDS and mail gateway, and import the full indicator list from the Talos GitHub repository into your EDR and SIEM. Block the delivery domains microsoft-flash[.]com and wps-cn[.]com.

2. Hunt on the endpoint

The genuine slc.dll lives in C:\Windows\System32, and GatherOsState.exe has no business on an office laptop. In Microsoft Defender for Endpoint, these queries find both:

DeviceImageLoadEvents
| where FileName =~ "slc.dll" and not(FolderPath startswith @"C:\Windows\")
DeviceNetworkEvents
| where RemoteUrl has_any ("graph.microsoft.com", "login.microsoftonline.com")
| where InitiatingProcessFileName in~ ("gatherosstate.exe", "mshta.exe")

Widen the second query once it runs clean: list every process that reaches Graph, then remove the Office apps, Teams, OneDrive, Edge and your managed agents. Investigate anything left that you cannot tie to installed software. Also review mshta.exe launched from Outlook or a browser, and new Run key values in user hives since September 2025.

3. Close the entry points

Most staff never need HTA files. Block mshta.exe with App Control for Business (formerly WDAC) or AppLocker where you can, and at least change the .hta and .wsf file associations to open in Notepad. Move your own domains from DMARC p=none to p=quarantine and then p=reject, so that mail forged in your domain's name is rejected rather than delivered to your own staff. On inbound mail, quarantine messages that fail DMARC alignment instead of only tagging them, and flag inline images that link to *.pages.dev.

4. Limit which tenants your devices can talk to

Tenant restrictions v2 in Entra ID lets you block sign-ins from your devices to external tenants, enforced through Windows Group Policy, Global Secure Access or a proxy header. Microsoft's documentation does not say whether it stops an app-only client-credentials request, so test that against a tenant you control before counting on it. A TLS-inspecting proxy can at least log token requests to login.microsoftonline.com/<tenant ID>/ where the tenant ID is not yours.

5. If you find it

Isolate the host and rebuild it. An operator with a shell and file upload may have taken any document the user could open, so treat the data on it as read. Reset the user's password, revoke their sessions and refresh tokens, and check the same mailbox for the original lure to find other recipients.

The wider lesson

Allowlisting "Microsoft 365 traffic" at the proxy assumes every Graph request belongs to your tenant. Antino shows that the useful question is which process made the request and which tenant issued its token, and most networks cannot answer either today.

Our security operations team builds hunts like these into day-to-day detection, and our safeguarding and hardening work covers script host controls, DMARC enforcement and tenant restrictions. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: Cisco Talos, GBHackers, NetManageIT, Cyber Security News, Microsoft Learn: tenant restrictions v2.

Back to the blog, or read this post on the full site.