In a novel and alarming escalation of cyber‐espionage, attackers have developed a Windows backdoor, dubbed Antino, that fully embeds its command and control (C2) operations inside Microsoft 365 services. Rather than relying on external servers or custom network infrastructure, the malware exploits trusted Microsoft cloud tools—Outlook and OneDrive—for every stage of communication, instruction, and data exfiltration. This approach allows Antino to maintain stealth by sitting inside services many organizations already whitelist and heavily rely upon.
What is Antino and how it operates
Antino is crafted in Rust and exists both as an executable file and as a loadable library. Command and control is administered through Microsoft Graph, the API used for interacting with Microsoft services. Outlook handles instructions and responses between the operators and infected systems, while OneDrive functions as the platform for status reports, theft of files, and delivery of tools. Its newest version authenticates via an Entra ID application using saved credentials—no user login is required.
Every 10 seconds, the malware checks an Outlook mailbox for new commands and posts back results labeled with corresponding task identifiers. OneDrive is used to upload frequent “heartbeat” files, revealing the machine’s identity, OS, user, session, and campaign codes. Infected systems store stolen files in designated OneDrive folders and retrieve additional tools from staged folders—all without exposing a conventional C2 server to network monitoring.
Functionally, Antino supports system reconnaissance, launching shell and PowerShell commands, transferring files, executing arbitrary programs, and in-memory loading of extra code. It also includes an optional hiding measure: when a secondary payload sleeps, it encrypts itself to evade memory scanners, though the main Antino process remains visible and registry or script activity may still expose the infection.
Infiltration strategy and targets
The campaign using Antino began in September 2025 and targets a wide array of entities including government, defense, diplomatic, academic, and policy research bodies. As of July 2026, around 350 endpoints in eight countries—Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria—were compromised in at least 10 confirmed institutional environments and five probable ones. One intended target has also been identified.
Infection chains begin with phishing emails purporting to come from trusted institutions, using themes related to policy, international disputes, taxation, or government. Attachments include malicious documents or links disguised as attachments. Even when domain authentication like DMARC checks are in place, attackers exploited lax policies (e.g. monitoring-only enforcement) and spoofed visible sender names to evade detection.
The delivery chain is multi‐stage. It typically starts with HTA (.hta) or Windows Script Files (.wsf), encrypted JavaScript, and unsafe .NET object processing to launch a downloader entirely in memory. Next, a benign Microsoft‐signed executable is sideloaded alongside a malicious library. Legitimate Windows troubleshooting tools are used to execute PowerShell commands and establish persistence on infected devices.
Attribution is strongly linked to China. Researchers point to language artifacts, development clues, infrastructure overlaps, and targeting patterns as evidence. Although some similarities with activity tagged as Jewelbug have been observed, no financial motive has been confirmed for this campaign. It appears driven by intelligence gathering.
Indicators & mitigation
Defenders are supplied with a broad set of indicators of compromise—including SHA-256 hashes of malicious installers and payloads, URLs, domains used in phishing, file names abused for side-loading, and the specific Microsoft Graph endpoints and OneDrive paths involved in the heartbeat traffic. Among these are fake installer domains mimicking established software and decoy files themed around policy, legislative or international affairs.
The campaign underscores the danger when malware leverages widely trusted cloud services for C2, bypassing many traditional detection tools that rely on spotting external suspicious hosts. Defenders are advised to monitor unusual Graph app registrations, enforce strict domain authentication policies, apply strong enforcement of sender authentication (not just monitoring), and observe anomalies in OneDrive folder usage, heartbeat uploads, or Outlook mailbox traffic.
What this means: Antino exemplifies the next evolution in stealth malware—fully integrating with cloud ecosystems that many organizations treat as implicitly safe. The campaign’s scale and sophistication signal a future where malicious infrastructure hides in plain sight, using the tools enterprises count on. Going forward, success will depend on visibility into cloud API abuse, aggressive authentication enforcement, and user education to spot deceptive phishing—all of which must become part of standard defensive posture.