# Antino Backdoor Leverages M365 for Espionage Campaign

> Discover how the China-nexus threat actor UAT-11587 deploys the Rust-compiled Antino backdoor, utilizing Outlook and OneDrive for C2 operations.

- Published: 2026-10-03T02:55:18.000Z
- Severity: medium
- Category: Threat Intel
- Tags: Microsoft 365, Rust, Espionage, Phishing, Antino
- Author: Runtime Rebel Intel
- Primary source: https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html
- Canonical: https://runtimerebel.com/blog/antino-backdoor-leverages-m365-for-espionage-campaign

## Key points

- Government and policy organizations across Asia and the Middle East are targeted by a China-nexus espionage campaign.
- The campaign relies on spear-phishing emails featuring sophisticated Gmail attachment preview spoofs and HTA/WSF stagers.
- Defenders must monitor for suspicious DLL sideloading of GatherOsState.exe and abnormal Microsoft Graph API traffic patterns.

A newly documented espionage campaign has targeted government, policy, and academic organizations across Asia and the Middle East, deploying a sophisticated Rust-compiled implant known as the Antino [backdoor](/glossary#backdoor). According to [Cisco Talos](https://blog.talosintelligence.com/), the intrusion cluster is tracked under the identifier UAT-11587 and has impacted at least 16 entities across eight countries since September 2025. The adversary demonstrates significant regional targeting preferences, focusing on legislative, maritime, diplomatic, and civil defense sectors aligned with strategic interests in Beijing.

## Technical Analysis of the Antino Backdoor

The attack chain begins with carefully tailored spear-[phishing](/glossary#phishing) messages designed to bypass standard perimeter security controls. To maximize success rates against targets, UAT-11587 utilizes sender [spoofing](/glossary#spoofing) to circumvent SPF and DMARC checks. Furthermore, operators replicate Gmail's native attachment preview widget inside the email HTML body using Base64-encoded MIME parts and inline PNG images. This fake attachment widget links to an external Cloudflare Pages URL that serves an initial HTA or WSF stager.

Once the stager executes on the host, it triggers a multi-stage infection process:

* **Staging and Decryption:** A JavaScript downloader fetches and decrypts subsequent payloads, initiating a .NET deserialization chain.
* **Launcher Execution:** The chain loads a custom .NET downloader and launcher designated as `TestAssembly.dll`.
* **DLL Sideloading:** The final implant (`slc.dll`) is loaded via DLL sideloading using a legitimate Microsoft-signed binary, specifically `GatherOsState.exe`.

### Living-off-Trusted-Cloud Command and Control

Unlike traditional [malware](/glossary#malware) families that rely on dedicated external infrastructure, the Antino backdoor blends malicious traffic with legitimate cloud services. As detailed in the initial [The Hacker News report](https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html), the malware leverages Microsoft Graph to interact exclusively with Microsoft 365 applications for its command-and-control ([C2](/glossary#c2)) infrastructure.

Antino uses Outlook mailboxes and OneDrive cloud storage as dead drops. The backdoor checks an attacker-controlled Outlook folder every 10 seconds for messages bearing the subject prefix `command_req_[session_id]` to retrieve incoming instructions. For operational heartbeats and file transfers, the malware switches to OneDrive objects. Capabilities of the implant include host [reconnaissance](/glossary#reconnaissance), process enumeration, directory listing, PowerShell script execution, and in-memory shellcode loading via the Windows Scripted Diagnostics framework.

## Actionable Mitigations and Detection Strategies

Detecting living-off-the-land binaries and abused cloud services requires focused telemetry tuning rather than relying strictly on signature-based defenses. Security teams should implement the following [hardening](/glossary#hardening) and monitoring steps:

* **Monitor DLL Sideloading:** Audit execution telemetry for native Microsoft binaries such as `GatherOsState.exe` loading non-standard dynamic-link libraries from working directories.
* **Inspect M365 [API](/glossary#api) Usage:** Audit Microsoft Graph API activity and Azure AD logs for anomalous mailbox access patterns, recurring programmatic email queries with specific subject prefixes, and unusual OneDrive file synchronization behaviors.
* **[Endpoint](/glossary#endpoint) Behavioral Rules:** Deploy strict endpoint detection rules to flag the execution of HTA and WSF stagers spawning obfuscated JavaScript or executing PowerShell via native diagnostic components.

**Related:** [UAT-11587 Deploys Antino Backdoor Against Asian Governments](/blog/uat-11587-deploys-antino-backdoor-against-asian-governments), [HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2](/blog/hollowgraph-malware-leverages-microsoft-365-calendar-for-stealthy-c2)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/antino-backdoor-leverages-m365-for-espionage-campaign
