Back to Intelligence

Antino Backdoor Abuses Outlook and OneDrive for C2: Detection and Hardening Guide for China-Nexus Espionage Campaign

SA
Security Arsenal Team
October 2, 2026
11 min read

Cisco Talos has disclosed a previously undocumented backdoor, tracked as Antino, deployed in a targeted espionage campaign against government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar. The cluster is assessed as China-nexus. What makes Antino operationally significant for defenders is not its novelty as malware — it is its command-and-control architecture: the implant communicates over legitimate Microsoft 365 services, specifically Outlook and OneDrive, blending C2 traffic into sanctioned enterprise cloud traffic.

This is a defensive nightmare by design. When C2 rides inside TLS sessions to outlook.office365.com, graph.microsoft.com, and OneDrive endpoints, it bypasses most egress filtering, defeats domain-reputation tooling, and renders IP blocklists useless. Organizations operating in the targeted sectors — and any enterprise heavily invested in Microsoft 365 — need to shift detection from where the traffic goes to what is generating the traffic. This post breaks down the technique and delivers field-ready detection and hardening guidance.

Technical Analysis

Threat Overview

  • Implant: Antino (previously undocumented unauthorized access mechanism / backdoor)
  • Attribution: China-nexus threat actor (cluster tracked by Cisco Talos)
  • Targets: Government and policy organizations in Taiwan, India, Philippines, Cambodia, Pakistan, Thailand, Myanmar
  • C2 Channel: Microsoft 365 services — Outlook (mail-based tasking/exfil) and OneDrive (payload staging, file exchange)
  • Campaign status: Active and ongoing; espionage-motivated, not financially driven

How the C2 Mechanism Works (Defender's View)

Antino represents a mature evolution of the "living off trusted services" (LOTS) pattern. Rather than standing up attacker-controlled infrastructure, the implant authenticates to Microsoft 365 and abuses legitimate service APIs:

  1. Tasking via Outlook: The implant polls a mailbox (attacker-controlled or a compromised victim account) for instructions embedded in email — subject lines, body content, or attachments. Responses and collected data are written back as drafts or sent messages, keeping exfiltration inside normal mail flows.

  2. Staging via OneDrive: Payloads, collected documents, and secondary tooling are exchanged through OneDrive file upload/download operations. To a proxy log, this looks like routine sync activity.

  3. API abuse: Communication typically occurs via Microsoft Graph API or Exchange Web Services (EWS)/REST endpoints. The implant may use stolen tokens, hardcoded OAuth app credentials, or attacker-registered Azure AD application identities.

Why Traditional Detection Fails

  • Destination reputation is useless: Traffic terminates at Microsoft-owned IP space with valid certificates.
  • TLS inspection yields little: Even decrypted, the payload is a syntactically valid Graph/EWS API call.
  • Volume-based alerting misses it: Espionage implants are deliberately low-and-slow, with polling intervals measured in minutes to hours.

The reliable detection surface is therefore host-side behavior: which process is making these connections, and whether that process has any legitimate business reason to talk to the Microsoft 365 API plane. Outlook.exe, OneDrive.exe, browsers, and Teams talking to Microsoft 365 is normal. An unsigned binary in %APPDATA%, %ProgramData%, or a user profile temp directory holding persistent TLS sessions to graph.microsoft.com is not.

Exploitation Status

This is not a vulnerability-based intrusion — no CVE is associated with this campaign, and none should be invented. Antino is a post-compromise implant: initial access precedes its deployment (spear-phishing and credential theft are the typical vectors for this actor profile). The campaign is confirmed active in the wild against named government targets. Treat this as an ongoing espionage threat, not a theoretical one.

Detection & Response

The detections below target the highest-fidelity behavioral surface: non-standard processes communicating with the Microsoft 365 API plane, and mail/OneDrive API access from anomalous binaries. Tune the process allow-lists to your environment before production deployment.

Sigma Rules

YAML
---
title: Suspicious Process Network Connection to Microsoft 365 API Endpoints
id: 3f7a2b91-8c4d-4e1f-a6b2-9d5e7c1a8f34
status: experimental
description: Detects non-Office, non-browser processes establishing network connections to Microsoft Graph, Outlook, or OneDrive API endpoints. Consistent with Antino-style C2 abusing Microsoft 365 services as observed in the China-nexus espionage campaign targeting Asian government entities.
references:
  - https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html
  - https://attack.mitre.org/techniques/T1102/
author: Security Arsenal
date: 2026/10/15
tags:
  - attack.command_and_control
  - attack.t1102
  - attack.t1071.001
logsource:
  category: network_connection
  product: windows
detection:
  selection_destination:
    DestinationHostname|contains:
      - 'graph.microsoft.com'
      - 'outlook.office365.com'
      - 'outlook.office.com'
      - '-my.sharepoint.com'
      - 'graph.microsoft.us'
      - 'graph.microsoft.de'
  filter_known_processes:
    Image|endswith:
      - '\msedge.exe'
      - '\chrome.exe'
      - '\firefox.exe'
      - '\outlook.exe'
      - '\onedrive.exe'
      - '\onedrivestandaloneupdater.exe'
      - '\filecoauth.exe'
      - '\teams.exe'
      - '\ms-teams.exe'
      - '\winword.exe'
      - '\excel.exe'
      - '\powerpnt.exe'
      - '\lync.exe'
      - '\msteams.exe'
      - '\searchprotocolhost.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
  condition: selection_destination and not filter_known_processes
falsepositives:
  - Legitimate third-party backup, DLP, or eDiscovery tools integrating with Microsoft 365
  - Custom line-of-business applications using Graph API
level: high
---
title: Unsigned Binary in User Profile Connecting to Cloud Storage or Mail APIs
id: 8b3e5c24-1f6a-4d9e-b7c3-2a8f4e6d9b15
status: experimental
description: Detects executables running from user-writable directories (AppData, ProgramData, Temp) making network connections to cloud mail or file storage services. Antino-class implants commonly reside in user profile paths while tunneling C2 through trusted SaaS.
references:
  - https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html
  - https://attack.mitre.org/techniques/T1102/002/
author: Security Arsenal
date: 2026/10/15
tags:
  - attack.command_and_control
  - attack.t1102.002
logsource:
  category: network_connection
  product: windows
detection:
  selection_path:
    Image|contains:
      - '\AppData\Local\Temp\'
      - '\AppData\Roaming\'
      - '\ProgramData\'
      - '\Users\Public\'
  selection_cloud:
    DestinationHostname|contains:
      - 'graph.microsoft.com'
      - 'outlook.office365.com'
      - 'sharepoint.com'
      - 'onedrive'
      - 'mail.google.com'
      - 'dropbox.com'
  filter_onedrive_client:
    Image|endswith:
      - '\AppData\Local\Microsoft\OneDrive\OneDrive.exe'
  condition: selection_path and selection_cloud and not filter_onedrive_client
falsepositives:
  - Portable applications syncing to cloud storage
  - User-installed sync utilities
level: high
---
title: Office Application Spawning Script or Command Interpreter
id: 5c9d1f73-2e8b-4a6c-9d4f-7b1e3a5c8d26
status: experimental
description: Detects Office productivity applications spawning command shells or script interpreters. A common delivery and execution chain for implants like Antino following spear-phish initial access against government targets.
references:
  - https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/10/15
tags:
  - attack.execution
  - attack.t1059
  - attack.t1204.002
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\winword.exe'
      - '\excel.exe'
      - '\powerpnt.exe'
      - '\outlook.exe'
      - '\msaccess.exe'
      - '\mspub.exe'
      - '\visio.exe'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\rundll32.exe'
      - '\regsvr32.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Rare legitimate macro-driven workflows (finance templates, ERP integrations)
level: high

KQL — Microsoft Sentinel / Defender

This hunt surfaces processes with no legitimate reason to speak to the Microsoft 365 API plane. Run it as a scheduled analytic rule with entity mapping on Account and Host. Expect to build an environment-specific allow-list on first pass — treat every hit as requiring triage.

KQL — Microsoft Sentinel / Defender
let M365ApiHosts = dynamic(["graph.microsoft.com", "outlook.office365.com", "outlook.office.com", "graph.microsoft.us", "substrate.office.com"]);
let KnownClients = dynamic(["msedge.exe", "chrome.exe", "firefox.exe", "outlook.exe", "onedrive.exe", "filecoauth.exe", "ms-teams.exe", "msteams.exe", "teams.exe", "winword.exe", "excel.exe", "powerpnt.exe", "searchprotocolhost.exe"]);
DeviceNetworkEvents
| where TimeGenerated > ago(24h)
| where ActionType == "ConnectionSuccess"
| where RemoteUrl has_any (M365ApiHosts) or RemoteUrl endswith "sharepoint.com"
| where InitiatingProcessFileName !in~ (KnownClients)
| where InitiatingProcessFileName !in~ ("powershell.exe", "pwsh.exe")  // admin Graph usage; hunt separately
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessFolderPath,
    InitiatingProcessSHA256, InitiatingProcessCommandLine, InitiatingProcessAccountName,
    RemoteUrl, RemoteIP, RemotePort
| extend SuspiciousPath = iff(InitiatingProcessFolderPath has_any ("\\AppData\\", "\\ProgramData\\", "\\Users\\Public\\", "\\Temp\\"), "HIGH", "REVIEW")
| sort by SuspiciousPath asc, TimeGenerated desc

Companion query for the Azure AD side — flag consented OAuth applications with mail/Files scopes, which is how an implant like Antino obtains durable API access:

KQL — Microsoft Sentinel / Defender
AuditLogs
| where TimeGenerated > ago(30d)
| where OperationName == "Consent to application"
| mv-expand TargetResources
| mv-expand TargetResources.modifiedProperties
| where TargetResources.modifiedProperties.displayName == "ConsentType"
| extend ConsentPerms = tostring(TargetResources.modifiedProperties.newValue)
| where ConsentPerms has_any ("Mail.Read", "Mail.ReadWrite", "Mail.Send", "Files.ReadWrite", "Files.ReadWrite.All", "offline_access")
| project TimeGenerated, AppName = tostring(TargetResources.displayName), AppId = tostring(TargetResources.id),
    ConsentPerms, InitiatedBy = tostring(InitiatedBy.user.userPrincipalName), Result
| sort by TimeGenerated desc

Velociraptor VQL

Use this artifact fleet-wide to enumerate processes holding active connections to Microsoft 365 infrastructure from unexpected binaries. Pair the output with authenticode signature verification in a follow-up enrichment.

VQL — Velociraptor
-- Hunt: Processes with active connections to Microsoft 365 API/C2-capable endpoints
-- Deploy as a hunt across endpoints; flag any non-allow-listed process
LET allowlist = ('outlook.exe', 'onedrive.exe', 'msedge.exe', 'chrome.exe',
                 'firefox.exe', 'ms-teams.exe', 'teams.exe', 'filecoauth.exe',
                 'winword.exe', 'excel.exe', 'powerpnt.exe', 'searchprotocolhost.exe')

SELECT Pid, Name, CommandLine, Exe, Username,
       netstat().RemoteIP AS RemoteIP,
       netstat().RemotePort AS RemotePort,
       netstat().Status AS ConnStatus
FROM pslist()
WHERE Name.ToLower() NOT IN allowlist
  AND netstat().RemotePort IN (443, 993, 995)
  AND netstat().Status =~ 'ESTAB'
ORDER BY Username, Pid

Note: Velociraptor's netstat() does not resolve remote hostnames. Correlate the returned RemoteIP values against published Microsoft 365 IP ranges, or enrich via DNS cache lookups, to confirm the connection terminates at Microsoft infrastructure. Any unsigned or user-profile-resident binary holding persistent 443 sessions to M365 ranges warrants memory acquisition.

Remediation & Hardening Script

This PowerShell audits the Azure-side exposure Antino-style implants depend on — illicit consent grants, apps with mail/file scopes, and mailbox auditing gaps — and hardens the tenant. Run the audit sections first; uncomment hardening actions only after review. Requires the Microsoft Graph PowerShell SDK with appropriate admin consent.

PowerShell
# Antino-style M365 C2 Exposure Audit & Hardening
# Run as Global Admin / Cloud App Admin. Review before enforcing.

Connect-MgGraph -Scopes "Application.Read.All","Directory.Read.All","AuditLog.Read.All","Policy.ReadWrite.PermissionGrant"

# 1. Enumerate all service principals holding high-risk mail/file Graph permissions
$riskyScopes = @("Mail.Read","Mail.ReadWrite","Mail.Send","Files.ReadWrite.All","Files.Read.All","Sites.ReadWrite.All")
$spGrants = Get-MgServicePrincipal -All | ForEach-Object {
    $sp = $_
    Get-MgServicePrincipalOauth2PermissionGrant -ServicePrincipalId $sp.Id -All -ErrorAction SilentlyContinue |
        Where-Object { $s = $_.Scope; $riskyScopes | Where-Object { $s -match $_ } } |
        Select-Object @{N='AppDisplayName';E={$sp.DisplayName}}, @{N='AppId';E={$sp.AppId}},
                      @{N='ConsentType';E={$_.ConsentType}}, Scope, ClientId, ResourceId
}
$spGrants | Format-Table -AutoSize
$spGrants | Export-Csv -Path "C:\IR\M365_RiskyConsentGrants.csv" -NoTypeInformation
Write-Host "[+] $($spGrants.Count) high-risk consent grants exported for review." -ForegroundColor Yellow

# 2. Find user-consented (non-admin) grants — the classic illicit-consent implant pattern
$userConsents = $spGrants | Where-Object { $_.ConsentType -eq 'Principal' }
$userConsents | Format-Table -AutoSize
if ($userConsents) { Write-Host "[!] USER-CONSENTED grants found — investigate each for implant persistence." -ForegroundColor Red }

# 3. Audit: disable user app consent entirely (recommended for targeted sectors)
# Uncomment after stakeholder review:
# Update-MgPolicyAuthorizationPolicy -DefaultUserRolePermissions @{ PermissionGrantPoliciesAssigned = @() }
# Write-Host "[+] User consent to applications disabled. Admin consent workflow now required." -ForegroundColor Green

# 4. Revoke a confirmed-malicious grant (replace IDs from investigation):
# Remove-MgOauth2PermissionGrant -OAuth2PermissionGrantId "<GrantId>"
# Remove-MgServicePrincipal -ServicePrincipalId "<SPObjectId>"

# 5. Verify mailbox auditing is tenant-enforced (detects implant mail access patterns)
Connect-ExchangeOnline
$notAudited = Get-Mailbox -ResultSize Unlimited -RecipientTypeDetails UserMailbox |
    Where-Object { -not $_.AuditEnabled } | Select-Object UserPrincipalName
if ($notAudited) {
    Write-Host "[!] $($notAudited.Count) mailboxes lack auditing. Enabling tenant-wide:" -ForegroundColor Red
    Set-OrganizationConfig -AuditDisabled $false
}

# 6. Alert policy check — ensure MailItemsAccessed (E5) or owner/delegate access alerts exist
Get-ProtectionAlert | Where-Object { $_.Name -match 'MailItemsAccessed|Mailbox' } |
    Select-Object Name, Disabled, NotificationEnabled | Format-Table -AutoSize

# 7. Endpoint sweep: unsigned binaries in user-writable paths with network capability indicators
$suspectPaths = @("$env:ProgramData", "$env:PUBLIC", "$env:TEMP")
Get-ChildItem -Path $suspectPaths -Recurse -Include *.exe,*.dll -ErrorAction SilentlyContinue |
    Where-Object { (Get-AuthenticodeSignature $_.FullName).Status -ne 'Valid' } |
    Select-Object FullName, Length, LastWriteTime,
        @{N='SigStatus';E={(Get-AuthenticodeSignature $_.FullName).Status}} |
    Export-Csv "C:\IR\UnsignedBinaries_UserPaths.csv" -NoTypeInformation
Write-Host "[+] Unsigned binary sweep complete. Correlate against network telemetry." -ForegroundColor Yellow

Remediation

1. Contain active compromise (if suspected):

  • Isolate affected hosts from the network; acquire memory before remediation — these implants are often fileless-resident or lightly touched to disk.
  • In Entra ID, enumerate and revoke all OAuth consent grants to non-sanctioned applications. Revoke refresh tokens for affected users (Revoke-MgUserSignInSession) and force credential resets. Token theft is the persistence mechanism — password reset alone does not evict an implant holding a refresh token.
  • Review mailbox audit logs for MailItemsAccessed and send/draft creation anomalies on accounts the implant used as a C2 mailbox.

2. Tenant hardening (the structural fix):

  • Disable user consent to applications tenant-wide; route all consent through an admin approval workflow. This closes the illicit-consent persistence path this actor class depends on.
  • Enforce Conditional Access application policies and restrict which client apps may access Graph/EWS. Disable legacy authentication protocols (IMAP/POP/SMTP basic auth) if not already done — they bypass MFA and are favored for mailbox-based C2.
  • Enable mailbox auditing tenant-wide and confirm MailItemsAccessed events flow to your SIEM (requires E5/Compliance add-on; without it you are blind to implant mail reads).

3. Egress and endpoint controls:

  • You cannot block Microsoft 365 at the proxy — so instrument the endpoint instead. Ensure Sysmon network-connection logging (or EDR equivalent) captures process-to-destination mapping; that is the detection surface the Sigma rules above consume.
  • Deploy Attack Surface Reduction rules blocking Office child processes — the phish-to-implant delivery chain for government-targeting actors reliably passes through a malicious document.

4. Threat hunting cadence:

  • Run the KQL hunt weekly at minimum; espionage implants poll slowly and a single 24-hour window will miss low-frequency beacons. Extend lookback to 7–30 days on a monthly deep hunt.
  • Cross-reference consented-app inventory against a known-good baseline monthly. Espionage tradecraft favors durable, quiet persistence — a single rogue app registration can survive for years.

5. Intelligence sharing:

  • If you operate in government or policy sectors in the affected countries, engage your national CERT and review Cisco Talos's full technical report for published IOCs (file hashes, mailbox indicators, app IDs) to layer onto the behavioral detections above.

Conclusion

Antino is a reminder that "trusted" cloud services are now primary C2 terrain. The defensive pivot is behavioral: identity-side consent hygiene, mailbox audit visibility, and host telemetry that answers which process is talking to Microsoft 365. Organizations in the targeted sectors should treat the hunts in this post as immediate action items, not backlog candidates.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.