Published on October 2, 2026

Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365


Severity

High

Detail

Researchers from Cisco Talos have identified a cyber espionage campaign attributed to UAT-11587, a threat actor assessed with high confidence to have links to China. The campaign delivers a Windows backdoor known as Antino, which abuses legitimate Microsoft 365 services for command-and-control (C2) communications and data exchange.

The campaign has reportedly been active since September 2025 and targeted government, defense, diplomatic, academic, and policy organizations across multiple countries. Cisco Talos identified approximately 350 compromised endpoints across eight countries, including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria.

Unlike traditional malware that relies on dedicated attacker-controlled servers, Antino leverages Microsoft 365 services, including Outlook, OneDrive, Microsoft Graph, and Entra ID, to conduct command-and-control operations. This approach allows malicious traffic to blend with legitimate cloud communications, making detection significantly more challenging.

The malware provides attackers with extensive remote access capabilities, enabling system reconnaissance, command execution, file transfers, additional payload deployment, and data exfiltration while maintaining persistent access to compromised systems.

How?

The attack typically begins with targeted spear-phishing emails impersonating trusted organizations. The emails contain decoy documents and links that mimic legitimate attachment previews, encouraging victims to download malicious content.

Upon execution, a multi-stage infection chain is initiated using Windows scripting components, encrypted JavaScript files, and malicious .NET components. The infection process ultimately loads a downloader into memory and opens a decoy document to avoid raising suspicion. The attackers then abuse DLL sideloading techniques by launching a legitimate Microsoft-signed executable, GatherOsState.exe, alongside a malicious library named slc[.]dll, which contains the Antino backdoor.

Once deployed, Antino authenticates to Microsoft 365 using attacker-controlled Entra ID application credentials and communicates through Microsoft Graph APIs. The malware periodically checks attacker-controlled Outlook mailboxes for commands, retrieves instructions from email messages, executes tasks on the compromised endpoint, and returns results through the same communication channel.

OneDrive is used to store victim status information, stolen data, operational tools, and malware updates. Status information uploaded to OneDrive may include computer name, username, operating system details, session identifiers and campaign tracking information.

Researchers noted that all native command-and-control functionality resides within Microsoft 365 services, allowing attackers to avoid exposing traditional external C2 infrastructure.

Indicator of Compromises (IoCs)

The table below lists IoCs associated with the reported malicious activity.

TypeIndicatorDescription
Fileslc[.]dllAntino backdoor library
FileGatherOsState[.]exeMicrosoft-signed executable abused for DLL sideloading
FileTestAssembly[.]dllIn-memory downloader and launcher
Fileresult[.]ps1Attacker-controlled PowerShell script
Domainosc-cdn[.]comSpear-phishing sender domain
Domainmicrosoft-flash[.]comFake installer delivery domain
Domainwps-cn[.]comMalware delivery domain
IP Address103[.]27[.]110[.]220Historical malware hosting infrastructure
Path%LOCALAPPDATA%\Windows GatherOSStateKit\Persistent installation directory
Cloud Path/antino/heartbeats/{id}.jsonOneDrive heartbeat uploads
Cloud Path/antino_downloads/{file}Stolen data storage location
Cloud Path/antino_uploads/{file}Operator tool delivery location
Subject Patterncommand_req_[session_id]Outlook command request messages
Subject Patterncommand_res_[session_id]Outlook command response messages

Conclusion

The Antino campaign demonstrates how threat actors continue to abuse trusted cloud platforms to conceal malicious activity and evade conventional network-based detection mechanisms. By leveraging legitimate Microsoft 365 services such as Outlook, OneDrive, Microsoft Graph, and Entra ID for command-and-control operations, the threat actor significantly reduces reliance on traditional infrastructure that defenders commonly monitor and block.

The malware provides extensive remote-access and data-theft capabilities while targeting government, defense, diplomatic, and policy organizations across multiple countries. Organizations should closely monitor unusual Microsoft Graph activity, unexpected application registrations within Entra ID, abnormal Outlook and OneDrive usage patterns, suspicious PowerShell execution, and DLL sideloading behavior involving legitimate Microsoft-signed binaries. Enhanced monitoring of cloud-service abuse and targeted phishing campaigns is also recommended to improve detection of similar threats.

Source

https://cybersecuritynews.com/hackers-built-a-windows-backdoor/