Antino Backdoor Leverages Microsoft 365 for Covert Command and Control
A sophisticated new backdoor, dubbed Antino, has been discovered using Microsoft 365 services like Outlook and OneDrive for its entire command and control infrastructure, targeting government and defense organizations globally.

A novel Windows backdoor named Antino has emerged, ingeniously utilizing Microsoft 365 services as its native command and control (C2) infrastructure. This sophisticated malware transforms trusted platforms like Outlook for issuing instructions and OneDrive for data exfiltration and updates, effectively turning legitimate cloud services into covert communication channels. The campaign, identified by Cisco Talos and linked with high confidence to China, has been actively targeting government, defense, diplomatic, academic, and policy organizations across eight countries since September 2025.
Researchers uncovered approximately 350 compromised endpoints by July 2026, with affected institutions located in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria. The attackers employed highly tailored phishing emails, convincing decoy documents, and fake software installers to deliver the Antino backdoor. This strategy combines familiar user interfaces with cloud services that organizations routinely trust, making detection more challenging. Cisco Talos assessed the campaign as primarily focused on intelligence gathering rather than financial gain.
Written in Rust, Antino is available in both executable and library forms. Its core C2 mechanism relies on Microsoft Graph, the interface applications use to interact with Microsoft services. Outlook messages serve as the primary channel for transmitting commands and receiving responses, while OneDrive is used for registration, status updates, transferring stolen files, and delivering additional tools from the attackers. This approach bypasses traditional C2 server monitoring by embedding communications within legitimate cloud traffic.
The malware's authentication process leverages Entra ID applications, utilizing stored credentials without requiring interactive user logins. Antino checks a compromised Outlook mailbox every ten seconds for new instructions embedded within message bodies. It then posts responses back, allowing operators to correlate results with specific tasks. This method ensures that the C2 infrastructure remains hidden within the vast amount of legitimate email traffic.
OneDrive plays a crucial role in maintaining the backdoor's presence and facilitating data transfer. Every minute, Antino uploads a status file to a designated OneDrive folder, containing vital system information such as the computer name, username, platform, session identifier, and campaign code. Separate folders are used to store exfiltrated victim files and to receive any new tools deployed by the attackers.
Once installed, Antino possesses a range of capabilities, including system inspection, execution of shell and PowerShell commands, file transfer, program execution, and the ability to load additional code directly into memory. An optional concealment feature can encrypt secondary payloads while they are dormant, reducing their visibility to memory scanners without hiding the entire Antino process or guaranteeing evasion.
The initial infection vector involves sophisticated spear-phishing emails that impersonate trusted organizations. These emails often feature convincing decoy documents related to policy, legislation, or geopolitical events relevant to the target audience. Clicking on an apparent attachment redirects the victim to an attacker-controlled download link. The infection chain typically involves multiple stages, including Windows scripting components, encrypted JavaScript, and unsafe .NET object processing, culminating in the use of DLL sideloading to execute Antino under the guise of a legitimate Microsoft executable.
Cisco Talos based its attribution to China on several indicators, including document language settings, development artifacts, and the specific targeting patterns observed. While some overlaps were noted with previously reported activity, researchers maintained separate tracking for this campaign. The use of Windows troubleshooting components to establish persistence and execute PowerShell commands further highlights the attackers' efforts to blend in with normal system operations.