Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Antino Backdoor Hijacks Microsoft 365 Mailboxes as a Stealthy C2 Channel

A China‑linked espionage group deployed the Antino backdoor, turning Outlook mailboxes and OneDrive into a covert command‑and‑control channel. The technique highlights the need for continuous monitoring of cloud‑service activity to maintain audit‑ready evidence of access‑control enforcement.

LiveThreat™ Intelligence · 📅 October 03, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

Antino Backdoor Hijacks Microsoft 365 Mailboxes as a Stealthy C2 Channel

What Happened — A China‑linked espionage group (UAT‑11587) deployed the Rust‑based Antino backdoor on Windows hosts. The malware uses Microsoft Graph to read commands from a compromised Outlook mailbox and to upload stolen files to the victim’s OneDrive, blending C2 traffic with normal Office 365 activity. Initial infection is achieved through a targeted phishing email that spoofs a trusted domain and passes SPF/DMARC checks.

Why It Matters for Trust & Control Assurance

  • The attack demonstrates how legitimate SaaS services can be weaponised, underscoring the need for continuous monitoring of privileged cloud‑account activity and evidence of anomalous mailbox use.
  • Detecting and logging unusual Graph API calls provides the audit‑ready evidence required to prove that access controls over cloud resources are being enforced.
  • Continuous verification of mailbox and OneDrive permissions aligns with a control‑assurance program that can surface misuse before exfiltration succeeds.

Who Is Affected – Government agencies and policy organisations in Asia that rely on Microsoft 365 for email and file storage.

Recommended Actions

  • Enforce strict least‑privilege policies for Outlook and OneDrive accounts; require MFA and conditional access for any service‑account that can invoke Graph APIs.
  • Deploy UEBA or SIEM rules that flag non‑human mailbox activity, bulk file uploads, and atypical Graph API calls.
  • Conduct a focused audit of mailbox permissions and third‑party app consent grants; remediate any over‑privileged assignments. Source: https://securityaffairs.com/200264/apt/antino-backdoor-uses-your-inbox-as-its-control-panel.html

Technical Notes

  • Antino runs on 32‑ and 64‑bit Windows, provides PowerShell shell, in‑memory shellcode execution, and persistence.
  • C2 channel is entirely cloud‑based via Microsoft Graph (Outlook mailbox for commands, OneDrive for exfiltration).
  • Initial delivery leverages a crafted phishing email that passes SPF/DMARC by using a legitimate sending domain while spoofing the visible “From” address. Source: https://securityaffairs.com/200264/apt/antino-backdoor-uses-your-inbox-as-its-control-panel.html
📰 Original Source
https://securityaffairs.com/200264/apt/antino-backdoor-uses-your-inbox-as-its-control-panel.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →