MalwareTips News Antino backdoor hides espionage traffic inside Microsoft 365

Have you received an email where an attachment preview unexpectedly opened a download website?

  • Yes, and I reported it

    Votes: 0 0.0%
  • Yes, but I did not report it

    Votes: 0 0.0%
  • No

    Votes: 0 0.0%
  • I am not sure

    Votes: 0 0.0%

  • Total voters
    0

News Now

Happening Now
Verified
MalwareTips-news-161.jpg

Image: Cisco Talos

A China-linked campaign has targeted government, defense, research and policy organizations across Asia with a Windows backdoor called Antino. The operation affected or targeted at least 16 institutional environments, with roughly 350 compromised devices identified across eight countries.


Government and policy groups are the main targets​

Cisco Talos says the campaign focused on public-sector and national-security-adjacent organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. Targets included government departments, diplomatic services, defense bodies, universities, think tanks and civil society groups.

Talos assesses with high confidence that the tracked actor, UAT-11587, has a China nexus. It assesses with moderate confidence that the sustained access and information collection supported an intelligence-gathering operation.

Emails imitate trusted senders and Gmail​

Attackers tailored phishing messages to their recipients and sometimes displayed the identity of a trusted organization in the visible From field. In one reviewed message, email authentication detected the mismatch, but the impersonated domain’s monitoring-only DMARC policy allowed delivery.

Some emails recreated Gmail’s attachment preview inside the message. The realistic-looking card was actually a link to attacker-controlled Cloudflare Pages infrastructure, where a recipient identifier could be logged.

  • Treat an attachment preview as suspicious if clicking it opens a website or downloads an HTA file instead of showing the expected document.
  • Organizations in the targeted sectors should review email and endpoint records for oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev and unexpected mshta.exe activity.
  • Report messages using unusually specific political, diplomatic, tax or security documents when the sender or delivery method is unexpected.

Antino uses Outlook and OneDrive for control​

Antino is a Windows backdoor written in Rust. It can inspect an infected computer, run shell and PowerShell commands, transfer files, load code directly into memory and maintain persistent access.

Instead of relying on a conspicuous dedicated command server, the malware communicates through Microsoft 365. It uses Microsoft Graph, a service for accessing Microsoft cloud applications, to exchange data through Outlook and OneDrive objects.

The observed infection chain begins with an HTA file executed by Windows’ mshta.exe component. Later stages load Antino by making the legitimate Microsoft-signed GatherOsState.exe program sideload a malicious slc.dll from the same folder.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top