A spear-phishing email arrives. It looks like a routine message from a trusted sender, and it contains what appears to be an attachment preview, rendered exactly the way a legitimate email client would display it. There is no suspicious file to download, no obvious link to a disreputable domain, just a familiar interface that invites a click.
That click is all it takes to begin a five-stage infection chain that ends with a custom Rust-compiled backdoor running quietly on the machine, receiving its instructions through the victim's own email and cloud storage accounts.
This is the Antino backdoor, and it represents a significant evolution in how state-linked threat actors hide their presence inside the infrastructure that organizations already trust.
Important Disclaimer
This article is intended for educational and defensive purposes only, and the information shared here is meant to help security professionals understand how this threat operates so they can better protect their systems.
Do not use these techniques against systems you do not own or do not have explicit written permission to test, because unauthorized testing is illegal in most jurisdictions.
The author assumes no liability for any damages, legal consequences, or other outcomes resulting from the use or misuse of this information, so always obtain proper authorization before conducting any testing, and stay legal, stay ethical, stay responsible.
What Is the Antino Backdoor?
Antino is a Windows backdoor coded using the Rust programming language. It was discovered by Cisco Talos in the context of a spear-phishing attack on the Taiwanese academic, think-tank, and civil society policy community.
UAT-11587 is the threat actor behind this campaign, and it is assessed with a high level of certainty by Talos as China-nexus based on several corroborated indicators, such as the Simplified Chinese metadata in the lure documents, the UTC+08:00 time zone offset in the email headers, and the Rust package mirror in the Cargo registry paths.
Talos detected the campaign in September 2025, and by July 2026, the operation has grown to sixteen impacted or targeted institutional environments from eight different countries with about 350 compromised endpoints.
The targeting is strategic rather than opportunistic. Affected sectors include defense and military, executive government, foreign affairs, law enforcement, legislative institutions, government IT services, think tanks, universities, and civil society organizations.
Why the Command-and-Control Model Matters
The most significant feature of Antino is not its capabilities, which are standard for a backdoor, but where it lives.
Traditional malware calls home to a dedicated server, and defenders have learned to look for that pattern, monitoring for connections to unfamiliar domains and blocking infrastructure associated with known threats.
Antino does not do that. It uses Microsoft 365 as its native command-and-control channel, interacting with Outlook and OneDrive through the Microsoft Graph API.
The implications are substantial. The traffic goes to Microsoft, which every organization already trusts and allows. The command channel is the victim's own mailbox. The data transfer path is the victim's own cloud storage.
This is what security researchers call a dead drop, a technique where the attacker and the malware communicate through a shared location rather than directly, and it is exceptionally difficult to detect because nothing about the traffic is anomalous at the network layer.
How the Attack Unfolds
The infection chain has five stages, and each one is designed to look like something legitimate.
Stage 1: The Phishing Email
This campaign starts with sending out spear-phishing emails via Migadu, a mail service, in which the attacker uses his own domain as the envelope sender and shows the name of the trusted organization as the sender.
This technique exploits the difference between the envelope sender and the visible sender, which means SPF checks pass for the attacker's domain while the recipient sees a familiar name in their inbox.
The emails contain a replica of a legitimate attachment preview widget, built from inline images and wrapped in a link to a Cloudflare Pages URL, and because it is rendered in the email body, it looks indistinguishable from a real attachment.
Stage 2: The Initial Stager
Clicking the fake attachment leads to an HTA or WSF file, which is a script-based format that Windows executes natively, and which is often overlooked because it is not an executable.
This stager retrieves a JavaScript downloader, which then retrieves and decrypts the next component.
Stage 3: The .NET Downloader
The JavaScript downloader triggers a .NET deserialization chain that loads a DLL, and this DLL is responsible for three actions, it downloads and opens a decoy document so the user believes they received what they clicked on, it downloads a decoy calculator executable, and it downloads and launches the Antino implant itself.
Stage 4: DLL Sideloading
DLL sideloading is used to launch the implant whereby a Microsoft signed binary loads a malicious DLL. In this case, the legitimate binary is called GatherOsState.exe.
This is important because the binary has been signed and is trustworthy, which means that any security tools based on signature validation won't trigger anything, and the malicious DLL will execute trusted by the legitimate process.
Stage 5: The Antino Backdoor
After execution, Antino starts communicating with Microsoft 365 and the features available are host reconnaissance, command execution using shell and PowerShell, file transfer, memory-based shellcode loading, and persistence.
It fetches commands from an Outlook mailbox folder every ten seconds, looking for messages with a specific subject prefix, and it uses OneDrive for heartbeat signals and file transfer.
The backdoor also abuses the Windows Scripted Diagnostics framework to execute PowerShell, which complicates behavioral attribution because the PowerShell activity originates from a legitimate Windows component rather than from the implant itself.
Why Detection Is So Difficult
Antino is a case study in why modern espionage campaigns are so hard to catch.
The traffic goes to Microsoft, which is allowed. The command channel is the user's own mailbox, which is expected. The file transfer path is the user's own cloud storage, which is normal. The implant runs inside a signed Microsoft binary, which is trusted.
There is no obvious indicator to block, no suspicious domain to add to a blocklist, and no anomalous network connection to alert on.
Talos noted that the abuse of the Windows Scripted Diagnostics framework complicates attribution to the implant, even though it does not eliminate observable PowerShell, file creation, or registry telemetry.
The attacker has essentially hidden inside the infrastructure that defenders are most reluctant to restrict, because restricting it would break legitimate business operations.
Who Is Behind It and What They Want
Talos assesses with moderate confidence that UAT-11587 is conducting an intelligence-gathering operation, and the targeting supports that assessment.
The lures and targets include Taiwanese political, legislative, civil defense, and policy research subjects, along with regional government, maritime, diplomatic, and security themes, and this collection focus is consistent with China-nexus interests.
The campaign expanded beyond Taiwan throughout 2026, with activity affecting or targeting organizations in India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria, and the largest concentrated wave occurred on June 8 and 9, 2026, when Talos identified around fifty-seven newly observed endpoints associated with India.
There is some overlap with a cluster tracked as Jewelbug, which Symantec characterized as a China-based hackers-for-hire group conducting both espionage and cryptocurrency fraud, but Talos could not independently verify a connection between the espionage campaign and the financially motivated activity, so it tracks UAT-11587 as a separate activity set.
Real Scenarios
Scenario 1: The Government Policy Analyst
The Setup
A policy analyst at a government research institution receives an email that appears to be from a colleague at a partner organization, and the email contains what looks like a PDF attachment preview.
The Attack
The analyst clicks the preview, which opens a Cloudflare-hosted page that downloads an HTA file, and the infection chain proceeds through the JavaScript downloader, the .NET deserializer, and the DLL sideloading stage, with a decoy document displayed so the analyst believes they received the file.
The Result
Antino establishes persistence, and the analyst's mailbox becomes the command channel for the attacker, who can now read internal communications, exfiltrate documents through OneDrive, and execute commands on the machine.
The Lesson
The attachment preview was the deception, and the analyst had no reason to suspect that clicking a preview would lead to a backdoor.
Scenario 2: The Think Tank Researcher
The Setup
A researcher employed by a policy think tank receives an email that seems to be coming from a government contact, along with an attachment that correctly previews as a document.
The Attack
The infection process installs Antino, which then starts checking for commands every ten seconds from an Outlook folder, using the credentials of the researcher's own, authenticated connection.
The Result
Persistent access is achieved, and since the command channel is the same researcher's mailbox, the traffic is part of regular email behavior that is undetectable by any security software.
The Lesson
The command channel is the account itself, thus nothing out of the ordinary is detected via the network monitoring channels.
Scenario 3: The University Research Department
The Setup
A university research department focused on international security issues receives a spear-phishing email with a lure tailored to their published work.
The Attack
The email contains a fake attachment widget that leads to the infection chain, and Antino is deployed using the signed GatherOsState.exe binary.
The Result
The backdoor uses the university's Microsoft 365 tenant for command and control, and the attacker moves laterally through the institution over several weeks.
The Lesson
Educational institutions are attractive targets because they hold valuable research and often have less mature security controls than government agencies.
How to Defend Against Antino
Defending against this class of threat requires a combination of monitoring, configuration, and detection that goes beyond traditional network controls.
1. Check for Any Suspicious Script Execution
It is always advised to be wary of any activity related to mshta.exe and wscript.exe, especially when they connect to any cloud storage service or connect where they shouldn’t.
2. Investigate Any Suspicious Activity through Microsoft Graph API
Look for any suspicious activities through Microsoft Graph API using Microsoft 365 audit log in connection to Graph API use, suspicious access to Outlook folders, and other suspicious activities with OAuth 2.0 client credential.
3. Detect DLL Sideloading
Keep track of legitimate and signed executables which load DLLs from inappropriate sources, as well as GatherOsState.exe or any similar executables used by Microsoft which make network connections.
4. Enable DMARC Policies
Although Antino relies on sender spoofing through misconfiguration rather than lack of sender domain verification, using DMARC reduces the risks of sender domain spoofing for all campaigns.
5. Examine Registry Entries for Any Persistency Method
The malware makes use of persistence method through the registry, therefore be wary of any Run keys associated with executables or scripts.
6. Watch for PowerShell from Scripted Diagnostics
The abuse of the Windows Scripted Diagnostics framework means PowerShell activity may originate from an unexpected parent process, so correlate PowerShell execution with process lineage rather than looking at PowerShell alone.
7. Restrict Outbound Access Where Possible
While blocking Microsoft 365 is not an option, restricting which applications can make Graph API calls, and monitoring for unusual patterns, reduces the attacker's ability to blend in.
8. Conduct Memory Forensics
The reason for this is because the malware utilizes in-memory shellcode injection techniques which mean that traditional disk-based forensics may be insufficient in detecting the infection.
9. Isolate and Investigate
In case of a detection of any Antino activity, it is recommended that isolation of the compromised endpoints be done and an investigation of suspicious changes be performed on Microsoft 365 mailboxes and OneDrive contents.
10. Review Lure Content Carefully
The fake attachment widget is the delivery mechanism, so train users to be suspicious of attachment previews that require clicking a link, and configure email clients to render fewer external resources where possible.
Quick Reference: Antino Defense Checklist
|
Defense Layer |
Action |
|
|
Enforce DMARC, train users on fake attachment previews |
|
Endpoint |
Monitor mshta.exe, wscript.exe, and DLL sideloading |
|
Cloud |
Investigate anomalous Graph API and OneDrive activity |
|
Registry |
Alert on new Run keys pointing to unusual scripts |
|
PowerShell |
Correlate execution with parent process lineage |
|
Network |
Monitor for unusual connections to Microsoft 365 |
|
Forensics |
Use memory analysis for in-memory components |
|
Response |
Isolate endpoints and review Microsoft 365 audit logs |
The Bottom Line
The Antino backdoor is a reminder that the most dangerous threats are not always the ones that look dangerous, and that hiding inside trusted infrastructure is more effective than trying to evade detection at the network layer.
The command channel is the victim's own mailbox, the file transfer path is the victim's own cloud storage, and the implant runs inside a signed Microsoft binary. There is nothing obvious to block, because everything the malware uses is something the organization needs.
Defending against this class of threat means monitoring how trusted services are used rather than whether they are used, correlating behavior across layers rather than looking for single indicators, and accepting that some of the most important detection signals live in the audit logs of the services you already trust.
The attackers have learned to hide in plain sight, and the defense has to learn to look there too.
FAQ Section
What is the Antino backdoor?
Antino is a Rust-compiled Windows backdoor used by a China-nexus threat actor tracked as UAT-11587, which targets government and policy organizations across Asia.
How does Antino communicate with its operators?
It uses Microsoft 365 as its command-and-control channel, fetching commands from an Outlook mailbox folder and using OneDrive for heartbeat signals and file transfer.
Why is this command-and-control method so hard to detect?
Because the traffic goes to Microsoft, which every organization already allows, and the command channel is the victim's own account, so nothing about the activity looks anomalous at the network layer.
How does Antino get onto a system?
It is delivered through spear-phishing emails containing a fake attachment preview, which leads to a five-stage infection chain involving HTA or WSF stagers, a JavaScript downloader, a .NET deserializer, and DLL sideloading.
Antino Campaign: Who Is the Threat Actor?
Cisco Talos highly believes that the threat actor is China-nexus due to Simplified Chinese language metadata, UTC+08:00 timestamps, and Cargo registry paths pointing out to a China-focused Rust mirror.
How Do I Respond to Suspected Antino Activities?
Immediately isolate the infected endpoints, analyze the Microsoft 365 audit logs to identify unauthorized access, perform memory forensics to locate the in-memory components, and investigate the changes in the mailbox contents or OneDrive objects.