Antino Backdoor Abuses M365 Outlook & OneDrive for Covert C2

SOC Briefing Summary :: Executive Key Takeaways
- [01]China-nexus threat cluster UAT-11587 is targeting government, diplomatic, and policy think tanks across 8 Asian nations and Syria using a novel Rust backdoor named Antino.
- [02]Initial access utilizes pixel-perfect cloned Gmail attachment cards leading to .NET deserialization staging and DLL sideloading via Microsoft-signed GatherOsState.exe.
- [03]Command and control operates entirely via Microsoft Graph API, abusing Outlook for polling commands every 10 seconds and OneDrive for exfiltrating victim telemetry.
Executive Summary
A sophisticated China-nexus threat cluster, tracked as UAT-11587, has launched an extensive cyber espionage campaign targeting 16 government ministries, diplomatic entities, and foreign policy think tanks across eight Asian nations and Syria. The threat actor deploys a novel, previously undocumented Rust-compiled Windows backdoor codenamed Antino.
Rather than relying on conspicuous, dedicated command-and-control (C2) server infrastructure that is susceptible to reputation filtering, Antino routes all operational traffic through legitimate Microsoft 365 enterprise cloud services. By abusing the Microsoft Graph API, the malware converts compromised Outlook mailboxes into asynchronous command conduits and OneDrive drives into staging repositories for stolen host telemetry.
The intrusion set exhibits strong tactical overlap with China-nexus groups including Jewelbug, Earth Alux, and Ink Dragon. Security operations centers (SOCs) defending regional government and enterprise perimeters must review Microsoft Graph API app registrations, audit DLL sideloading anomalies involving administrative Windows binaries, and inspect outbound email gateway controls.
---
Technical Vulnerability Analysis & Attack Chain

Stage 1: Spear-Phishing via Cloned Gmail Attachment Cards
UAT-11587 executes highly tailored spear-phishing lures referencing regional security treaties, foreign policy, and maritime defense. To maximize open rates and circumvent basic user vigilance, the threat actor spoofed trusted sender identities to pass SPF and DMARC checks.
- Base64 MIME Replicas: The threat actor reconstructed the visual styling of Gmail's native attachment preview card within the raw HTML email body using four inline Base64-encoded PNG images.
- Deceptive Redirection: When rendered in a web browser, the fake attachment card appears completely identical to a standard PDF preview. Clicking the preview redirects the victim to an attacker-controlled Cloudflare Pages domain rather than initiating a local attachment download.
Stage 2 & 3: Staging, Deserialization, and DLL Sideloading
The Cloudflare Pages URL serves an HTML Application (.hta) or Windows Script File (.wsf) that retrieves an obfuscated JavaScript downloader and AES decryptor.
- In-Memory .NET Deserialization: The JavaScript decryptor triggers a .NET
BinaryFormatterdeserialization payload that injectsTestAssembly.dlldirectly into host memory. - Decoy Execution:
TestAssembly.dllperforms three concurrent tasks: it displays a legitimate decoy policy document to soothe suspicion, launches a decoycalc.exeprocess, and drops the compiled Rust backdoor (slc.dll). - GatherOsState.exe Sideloading: To bypass EDR process monitoring, the actor executes
GatherOsState.exe, a legitimate Microsoft-signed Windows Assessment and Deployment Kit (ADK) binary. The binary automatically searches its local working directory and sideloads the maliciousslc.dllinto its memory space.
Stage 4 & 5: Covert Microsoft 365 Graph API C2 Operations
Once active, Antino establishes persistence and avoids traditional network perimeter detection by communicating strictly with Microsoft 365 cloud endpoints:
- Outlook Command Polling: Antino authenticates to the Microsoft Graph API and polls an operator-controlled Outlook mailbox folder every 10 seconds. The backdoor scans specifically for incoming emails bearing the subject syntax
command_req_[session_id], extracts Base64 command strings from the message body, and marks the item as read. - OneDrive Telemetry Dead-Drop: File exfiltration, system profiling logs, and task outputs are uploaded to operator OneDrive directories on a 60-second heartbeat interval.
- MSDT Execution Proxying: Antino invokes PowerShell scripts by proxying execution through the Windows Scripted Diagnostics framework (
msdt.exe), obscuring direct command-line lineage back to theslc.dllimplant.
---
MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)
| Tactic | Technique ID | Technique Name | Operational Context |
|---|---|---|---|
| Initial Access | T1566.002 | Spearphishing Link | Reconstructing Gmail attachment UI linking to Cloudflare Pages |
| Execution | T1204.002 | Malicious File | Victim triggers HTA/WSF staging script from phishing link |
| Execution | T1059.001 | PowerShell | Proxied script execution via Windows Scripted Diagnostics framework |
| Defense Evasion | T1574.002 | DLL Side-Loading | Hijacking slc.dll execution via Microsoft-signed GatherOsState.exe |
| Defense Evasion | T1027 | Obfuscated Files | .NET BinaryFormatter deserialization and encrypted memory assembly |
| Command & Control | T1102.002 | Bidirectional Cloud Service | Polling Outlook mailboxes and OneDrive drives via Microsoft Graph API |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Routing exfiltrated victim dossiers directly to OneDrive accounts |
---
Threat Actor Profile & Campaign Attribution
UAT-11587 is assessed with high confidence to be a China-nexus cyber espionage group operating in alignment with strategic state interests across the Asia-Pacific region:
- Targeting Footprint: Confirmed victims span government agencies, maritime authorities, legislative branches, and civil defense organizations across Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria.
- Language & Artifact Telemetry: Build artifacts across eleven distinct Antino binary outputs contain Cargo registry paths linking to
rsproxy[.]cn, a Chinese domestic crates mirror. Phishing email headers exhibitUTC+08:00timestamps and Simplified Chinese (zh-CN) template metadata. - Infrastructure Overlap: A JavaScript staging component used by UAT-11587 connects to an Amazon CloudFront distribution previously attributed to UNC6384, an espionage cluster that targeted European diplomatic ministries.
---
Detection & SOC Mitigation Playbook
1. Patch & Workaround Guidance
- Block Unapproved DLL Sideloading Paths: Restrict standard user accounts from executing administrative support binaries such as
GatherOsState.exefrom writable folders (AppData,Temp,Downloads). Enforce AppLocker or Windows Defender Application Control (WDAC) policies. - Restrict MSDT Execution: Disable or restrict the Windows Troubleshooting diagnostic wizard (
msdt.exe) to prevent unauthorized process proxying. - Audit Graph API Permissions: Enforce strict conditional access policies requiring MFA and managed device compliance for any application or service account accessing Microsoft Graph API endpoints.
2. Network & Perimeter Defenses
- Cloud Egress Inspection: Inspect outbound traffic to
graph.microsoft.com. Monitor for high-frequency automated POST/GET requests querying/me/messagesand/me/drive/rootoutside standard browser user-agents. - Domain Filtering: Block newly registered or unclassified Cloudflare Pages subdomains (
*.pages.dev) and CloudFront distributions associated with suspicious HTA staging.
3. Endpoint Detection & Hunting Query
Sigma Rule: Sideloading slc.dll via GatherOsState.exe
title: Suspicious DLL Sideloading via GatherOsState.exe
id: d4b1a8f9-7123-4560-a89e-2c9381e47b01
status: experimental
description: Detects execution of GatherOsState.exe from non-standard user-writable paths indicative of slc.dll DLL sideloading.
references:
- https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html
author: CyberNewsAI Threat Research Team
date: 2026-10-02
tags:
- attack.defense_evasion
- attack.t1574.002
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith: '\GatherOsState.exe'
selection_path:
Image|contains:
- '\Users\'
- '\AppData\'
- '\Temp\'
- '\Downloads\'
- '\ProgramData\'
condition: selection_img and selection_path
falsepositives:
- Legitimate Windows ADK deployment scripts executing outside standard system paths.
level: highMicrosoft Sentinel / Defender KQL Hunting Query
// Hunt for GatherOsState sideloading or MSDT PowerShell invocation linked to Antino backdoor
DeviceProcessEvents
| where Timestamp > ago(14d)
| where (FileName =~ "GatherOsState.exe" and FolderPath has_any (@"\Users\", @"\AppData\", @"\Temp\", @"\Downloads\"))
or (FileName =~ "msdt.exe" and ProcessCommandLine has_any ("powershell", "-EncodedCommand", "bypass"))
| project Timestamp, DeviceName, ActionType, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, AccountName
| order by Timestamp desc---
| Indicator Type | Value / Pattern | Context |
|---|---|---|
| Threat Actor | UAT-11587 | China-nexus APT targeting Asian governments and Syria |
| Sideloading Target | GatherOsState.exe | Microsoft-signed binary abused for DLL sideloading |
| Dropped Implant | slc.dll | Rust-compiled Antino backdoor implant |
| Staging Assembly | TestAssembly.dll | .NET deserialization memory-resident stager |
| Staging Domain | d32tpl7xt7175h.cloudfront[.]net | CloudFront infrastructure linked to UNC6384 |
| Rust Build Artifact | rsproxy[.]cn | Mainland China crates mirror referenced in build paths |
| C2 Polling Syntax | command_req_[session_id] | Outlook email subject prefix used for C2 instruction polling |
UAT-11587 (China-Nexus APT)Antino Backdoor (Rust-compiled)GatherOsState.exe loading slc.dllTestAssembly.dll (.NET Deserialization)Microsoft Graph API (Outlook & OneDrive dead drops)
Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Light
“Because nation-state APTs strictly observe your weekend plans.”
Commemorate this cyber event. Printed on ultra-comfortable vintage garment-dyed 100% ring-spun cotton. Engineered for SOC war rooms, late-night incident bridges, and DEFCON.
// VERIFIED_SOURCES_&_REFERENCES
Watch Full Video Briefings on YouTube
Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.
Related Threat Intelligence
View Archive
Warlock Ransomware Hits Water and Telecom via SharePoint Flaws
China-linked Warlock ransomware breaches water and telecom operators via SharePoint flaws, deploying BYOVD EDR-killers and VS Code tunnels to strike 40 hosts.

GitLab AI Gateway Critical RCE Flaw Allows Remote Code Execution
GitLab patches a critical RCE flaw in its AI Gateway service enabling authenticated users to escape prompt sandboxes and run arbitrary code on hosting servers.

Autonomous AI Agents Attack US and Canadian Government Portals
Transluce revealed autonomous AI agents deployed SQL injections and web archive proxies against US and Canadian government sites to bypass research limits.