Antino Backdoor Abuses M365 Outlook & OneDrive for Covert C2

•By CyberNewsAI Admin•VERIFIED INTEL
Antino Backdoor Architecture and Microsoft 365 Dead-Drop Command and Control Telemetry

SOC Briefing Summary :: Executive Key Takeaways

  • [01]China-nexus threat cluster UAT-11587 is targeting government, diplomatic, and policy think tanks across 8 Asian nations and Syria using a novel Rust backdoor named Antino.
  • [02]Initial access utilizes pixel-perfect cloned Gmail attachment cards leading to .NET deserialization staging and DLL sideloading via Microsoft-signed GatherOsState.exe.
  • [03]Command and control operates entirely via Microsoft Graph API, abusing Outlook for polling commands every 10 seconds and OneDrive for exfiltrating victim telemetry.
SHARE INTEL:Reddit

Executive Summary

A sophisticated China-nexus threat cluster, tracked as UAT-11587, has launched an extensive cyber espionage campaign targeting 16 government ministries, diplomatic entities, and foreign policy think tanks across eight Asian nations and Syria. The threat actor deploys a novel, previously undocumented Rust-compiled Windows backdoor codenamed Antino.

Rather than relying on conspicuous, dedicated command-and-control (C2) server infrastructure that is susceptible to reputation filtering, Antino routes all operational traffic through legitimate Microsoft 365 enterprise cloud services. By abusing the Microsoft Graph API, the malware converts compromised Outlook mailboxes into asynchronous command conduits and OneDrive drives into staging repositories for stolen host telemetry.

The intrusion set exhibits strong tactical overlap with China-nexus groups including Jewelbug, Earth Alux, and Ink Dragon. Security operations centers (SOCs) defending regional government and enterprise perimeters must review Microsoft Graph API app registrations, audit DLL sideloading anomalies involving administrative Windows binaries, and inspect outbound email gateway controls.

---

Technical Vulnerability Analysis & Attack Chain

Attack Chain Flow
// Attack Chain Flow

Stage 1: Spear-Phishing via Cloned Gmail Attachment Cards

UAT-11587 executes highly tailored spear-phishing lures referencing regional security treaties, foreign policy, and maritime defense. To maximize open rates and circumvent basic user vigilance, the threat actor spoofed trusted sender identities to pass SPF and DMARC checks.

  • Base64 MIME Replicas: The threat actor reconstructed the visual styling of Gmail's native attachment preview card within the raw HTML email body using four inline Base64-encoded PNG images.
  • Deceptive Redirection: When rendered in a web browser, the fake attachment card appears completely identical to a standard PDF preview. Clicking the preview redirects the victim to an attacker-controlled Cloudflare Pages domain rather than initiating a local attachment download.

Stage 2 & 3: Staging, Deserialization, and DLL Sideloading

The Cloudflare Pages URL serves an HTML Application (.hta) or Windows Script File (.wsf) that retrieves an obfuscated JavaScript downloader and AES decryptor.

  • In-Memory .NET Deserialization: The JavaScript decryptor triggers a .NET BinaryFormatter deserialization payload that injects TestAssembly.dll directly into host memory.
  • Decoy Execution: TestAssembly.dll performs three concurrent tasks: it displays a legitimate decoy policy document to soothe suspicion, launches a decoy calc.exe process, and drops the compiled Rust backdoor (slc.dll).
  • GatherOsState.exe Sideloading: To bypass EDR process monitoring, the actor executes GatherOsState.exe, a legitimate Microsoft-signed Windows Assessment and Deployment Kit (ADK) binary. The binary automatically searches its local working directory and sideloads the malicious slc.dll into its memory space.

Stage 4 & 5: Covert Microsoft 365 Graph API C2 Operations

Once active, Antino establishes persistence and avoids traditional network perimeter detection by communicating strictly with Microsoft 365 cloud endpoints:

  • Outlook Command Polling: Antino authenticates to the Microsoft Graph API and polls an operator-controlled Outlook mailbox folder every 10 seconds. The backdoor scans specifically for incoming emails bearing the subject syntax command_req_[session_id], extracts Base64 command strings from the message body, and marks the item as read.
  • OneDrive Telemetry Dead-Drop: File exfiltration, system profiling logs, and task outputs are uploaded to operator OneDrive directories on a 60-second heartbeat interval.
  • MSDT Execution Proxying: Antino invokes PowerShell scripts by proxying execution through the Windows Scripted Diagnostics framework (msdt.exe), obscuring direct command-line lineage back to the slc.dll implant.

---

MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)

MITRE ATT&CK • OPERATIONAL TTP MAPPING
TacticTechnique IDTechnique NameOperational Context
Initial AccessT1566.002Spearphishing LinkReconstructing Gmail attachment UI linking to Cloudflare Pages
ExecutionT1204.002Malicious FileVictim triggers HTA/WSF staging script from phishing link
ExecutionT1059.001PowerShellProxied script execution via Windows Scripted Diagnostics framework
Defense EvasionT1574.002DLL Side-LoadingHijacking slc.dll execution via Microsoft-signed GatherOsState.exe
Defense EvasionT1027Obfuscated Files.NET BinaryFormatter deserialization and encrypted memory assembly
Command & ControlT1102.002Bidirectional Cloud ServicePolling Outlook mailboxes and OneDrive drives via Microsoft Graph API
ExfiltrationT1567.002Exfiltration to Cloud StorageRouting exfiltrated victim dossiers directly to OneDrive accounts

---

Threat Actor Profile & Campaign Attribution

UAT-11587 is assessed with high confidence to be a China-nexus cyber espionage group operating in alignment with strategic state interests across the Asia-Pacific region:

  • Targeting Footprint: Confirmed victims span government agencies, maritime authorities, legislative branches, and civil defense organizations across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria.
  • Language & Artifact Telemetry: Build artifacts across eleven distinct Antino binary outputs contain Cargo registry paths linking to rsproxy[.]cn, a Chinese domestic crates mirror. Phishing email headers exhibit UTC+08:00 timestamps and Simplified Chinese (zh-CN) template metadata.
  • Infrastructure Overlap: A JavaScript staging component used by UAT-11587 connects to an Amazon CloudFront distribution previously attributed to UNC6384, an espionage cluster that targeted European diplomatic ministries.

---

Detection & SOC Mitigation Playbook

1. Patch & Workaround Guidance

  • Block Unapproved DLL Sideloading Paths: Restrict standard user accounts from executing administrative support binaries such as GatherOsState.exe from writable folders (AppData, Temp, Downloads). Enforce AppLocker or Windows Defender Application Control (WDAC) policies.
  • Restrict MSDT Execution: Disable or restrict the Windows Troubleshooting diagnostic wizard (msdt.exe) to prevent unauthorized process proxying.
  • Audit Graph API Permissions: Enforce strict conditional access policies requiring MFA and managed device compliance for any application or service account accessing Microsoft Graph API endpoints.

2. Network & Perimeter Defenses

  • Cloud Egress Inspection: Inspect outbound traffic to graph.microsoft.com. Monitor for high-frequency automated POST/GET requests querying /me/messages and /me/drive/root outside standard browser user-agents.
  • Domain Filtering: Block newly registered or unclassified Cloudflare Pages subdomains (*.pages.dev) and CloudFront distributions associated with suspicious HTA staging.

3. Endpoint Detection & Hunting Query

Sigma Rule: Sideloading slc.dll via GatherOsState.exe

QUERY / DETECTION_RULE
SIGMA / YAML
title: Suspicious DLL Sideloading via GatherOsState.exe
id: d4b1a8f9-7123-4560-a89e-2c9381e47b01
status: experimental
description: Detects execution of GatherOsState.exe from non-standard user-writable paths indicative of slc.dll DLL sideloading.
references:
  - https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html
author: CyberNewsAI Threat Research Team
date: 2026-10-02
tags:
  - attack.defense_evasion
  - attack.t1574.002
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith: '\GatherOsState.exe'
  selection_path:
    Image|contains:
      - '\Users\'
      - '\AppData\'
      - '\Temp\'
      - '\Downloads\'
      - '\ProgramData\'
  condition: selection_img and selection_path
falsepositives:
  - Legitimate Windows ADK deployment scripts executing outside standard system paths.
level: high

Microsoft Sentinel / Defender KQL Hunting Query

QUERY / DETECTION_RULE
SENTINEL / KQL
// Hunt for GatherOsState sideloading or MSDT PowerShell invocation linked to Antino backdoor
DeviceProcessEvents
| where Timestamp > ago(14d)
| where (FileName =~ "GatherOsState.exe" and FolderPath has_any (@"\Users\", @"\AppData\", @"\Temp\", @"\Downloads\"))
    or (FileName =~ "msdt.exe" and ProcessCommandLine has_any ("powershell", "-EncodedCommand", "bypass"))
| project Timestamp, DeviceName, ActionType, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, AccountName
| order by Timestamp desc

---

Indicator TypeValue / PatternContext
Threat ActorUAT-11587China-nexus APT targeting Asian governments and Syria
Sideloading TargetGatherOsState.exeMicrosoft-signed binary abused for DLL sideloading
Dropped Implantslc.dllRust-compiled Antino backdoor implant
Staging AssemblyTestAssembly.dll.NET deserialization memory-resident stager
Staging Domaind32tpl7xt7175h.cloudfront[.]netCloudFront infrastructure linked to UNC6384
Rust Build Artifactrsproxy[.]cnMainland China crates mirror referenced in build paths
C2 Polling Syntaxcommand_req_[session_id]Outlook email subject prefix used for C2 instruction polling
Indicators of Compromise (IOCs)
5 Identified
Threat ClusterUAT-11587 (China-Nexus APT)
Malware FamilyAntino Backdoor (Rust-compiled)
DLL Sideloading TargetGatherOsState.exe loading slc.dll
Stager AssemblyTestAssembly.dll (.NET Deserialization)
C2 ChannelMicrosoft Graph API (Outlook & OneDrive dead drops)
// EVERGREEN RELIC // P1 INCIDENT
Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Light mockup

Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Light

“Because nation-state APTs strictly observe your weekend plans.”

Commemorate this cyber event. Printed on ultra-comfortable vintage garment-dyed 100% ring-spun cotton. Engineered for SOC war rooms, late-night incident bridges, and DEFCON.

Direct Armory Fulfillment$20
ACQUIRE RELIC
Fast US Shipping (2-4 Days)• 1-Click Apple / Google Pay
SHARE INTEL:Reddit
OPERATIONS_BROADCAST

Watch Full Video Briefings on YouTube

Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.

SUBSCRIBE_ON_YOUTUBE