Antino Backdoor Hijacks Microsoft 365 Mailboxes as a Stealthy C2 Channel
What Happened — A China‑linked espionage group (UAT‑11587) deployed the Rust‑based Antino backdoor on Windows hosts. The malware uses Microsoft Graph to read commands from a compromised Outlook mailbox and to upload stolen files to the victim’s OneDrive, blending C2 traffic with normal Office 365 activity. Initial infection is achieved through a targeted phishing email that spoofs a trusted domain and passes SPF/DMARC checks.
Why It Matters for Trust & Control Assurance
- The attack demonstrates how legitimate SaaS services can be weaponised, underscoring the need for continuous monitoring of privileged cloud‑account activity and evidence of anomalous mailbox use.
- Detecting and logging unusual Graph API calls provides the audit‑ready evidence required to prove that access controls over cloud resources are being enforced.
- Continuous verification of mailbox and OneDrive permissions aligns with a control‑assurance program that can surface misuse before exfiltration succeeds.
Who Is Affected – Government agencies and policy organisations in Asia that rely on Microsoft 365 for email and file storage.
Recommended Actions
- Enforce strict least‑privilege policies for Outlook and OneDrive accounts; require MFA and conditional access for any service‑account that can invoke Graph APIs.
- Deploy UEBA or SIEM rules that flag non‑human mailbox activity, bulk file uploads, and atypical Graph API calls.
- Conduct a focused audit of mailbox permissions and third‑party app consent grants; remediate any over‑privileged assignments. Source: https://securityaffairs.com/200264/apt/antino-backdoor-uses-your-inbox-as-its-control-panel.html
Technical Notes
- Antino runs on 32‑ and 64‑bit Windows, provides PowerShell shell, in‑memory shellcode execution, and persistence.
- C2 channel is entirely cloud‑based via Microsoft Graph (Outlook mailbox for commands, OneDrive for exfiltration).
- Initial delivery leverages a crafted phishing email that passes SPF/DMARC by using a legitimate sending domain while spoofing the visible “From” address. Source: https://securityaffairs.com/200264/apt/antino-backdoor-uses-your-inbox-as-its-control-panel.html