Antino is a Rust-compiled Windows backdoor used in China-nexus cyberespionage operations. It exists in 32-bit and 64-bit builds and in executable and DLL forms. Its capabilities include host and process reconnaissance, directory and file enumeration, command-shell and PowerShell execution, execution of operator-supplied programs, bidirectional file transfer, in-memory shellcode loading, and persistence through user-level Registry autorun entries. It abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components. It can also mask an in-memory shellcode payload by encrypting its memory during sleep and restoring it through exception handling.
Antino's native command-and-control channel operates exclusively through Microsoft 365 services accessed using Microsoft Graph. It exchanges commands and results through an attacker-controlled Outlook mailbox and uses OneDrive for heartbeat reporting, incoming operator tools, and exfiltrated files. This design allows its communications to blend with legitimate Microsoft cloud traffic.
Delivery mechanisms include tailored spear-phishing with geopolitical, government, diplomatic, and policy lures. Fake Gmail attachment previews lead victims into multistage HTA or WSF, JScript, and .NET downloader chains. Deployment commonly uses DLL sideloading through a legitimate Microsoft-signed Windows diagnostic executable. Antino is also distributed through fake Adobe Flash updates and bogus Adobe installers, including prompts presented to selected Windows users visiting compromised government webmail platforms. Some deployments install the malicious PDF Viewer browser extension alongside the backdoor.
Antino is associated with UAT-11587 and Jewelbug operations targeting government, defense, diplomatic, legislative, research, policy, and civil-society organizations across Asia and the Middle East. UAT-11587 is tracked separately from Jewelbug despite operational overlap; the two activity sets are not established as interchangeable.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UAT-11587 has deployed a previously undocumented Rust-compiled Windows backdoor known as Antino. The malware provides capabilities including host reconnaissance, command and PowerShell execution, file transfer, in-memory shellcode execution, and persistence.
The group uses its XG-Web remote-access framework, Antino backdoor, and malicious browser extensions to steal credentials, cookies, and sensitive data while maintaining access to victim networks.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
"a web hosting provider was compromised to inject JavaScript code into a common webmail installation used by multiple ministries associated with a Middle Eastern government. The watering hole campaign spanned 15 government webmail tenants" | "the malicious code activating on the login page and every mailbox view to exfiltrate cookies over a WebSocket connection and serve a next-stage payload"
“Antino,” a Rust-based Windows backdoor capable of reconnaissance, command execution, file transfer, shellcode loading, and persistence.
Exécution shell (cmd, powershell) via Windows Scripted Diagnostics (sdiagnhost.exe)
Exécution shell (cmd, powershell) via Windows Scripted Diagnostics (sdiagnhost.exe)
HTA-hosted Microsoft JScript retrieved encrypted resources, decrypted them using RC4, and executed the decrypted JScript orchestrator in memory.
“Encrypted JScript orchestrator,” “Encrypted BinaryFormatter resource,” and “PE section .cfg Obfuscated JSON configuration section.”
“flashcenter_pp_ax_install_en.exe Fake installer carrying standalone Antino” and “Standalone Antino fake-installer delivery.”
slc.dll = backdoor Antino [...] flashcenter_pp_ax_install_en.exe
Antino abuses the Windows Scripted Diagnostics framework: sdiageng.dll initializes the PCW package and sdiagnhost.exe executes the attacker-controlled result.ps1 script.
"Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control channel..."
“graph.microsoft.com Legitimate Microsoft Graph endpoint abused for C2” and the use of CloudFront, Cloudflare Pages, and Cloudflare R2 URLs for staged payload delivery.
C2 exclusivement via Microsoft Graph API (Outlook pour les commandes, OneDrive pour heartbeat et fichiers)
“graph.microsoft.com Legitimate Microsoft Graph endpoint abused for C2” and Cloud paths including “/antino/heartbeats/{id}.json,” “/antino_downloads/{file},” and “/antino_uploads/{file}.”
Le canal C2 utilise des dead drops : commandes reçues via emails Outlook [...] heartbeats JSON uploadés sur OneDrive
182 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Antino is a Rust-compiled Windows backdoor used for cyber espionage. It gathers system information, executes shell and PowerShell commands, transfers files, loads shellcode into memory, and maintains persistence. It uses Microsoft Graph to receive commands through Outlook and conduct heartbeat communications and file transfers through OneDrive, potentially complicating network-based detection. Delivery involves spear-phishing, multistage downloaders, and DLL sideloading. By July 2026, researchers had identified at least 16 affected or targeted institutional environments and approximately 350 compromised endpoints in the associated campaign.
Rust-based Windows backdoor used in UAT-11587's espionage campaign against government and policy organizations across Asia. Delivered through a multistage phishing chain, it is sideloaded as slc.dll by the signed GatherOsState.exe binary. Capabilities include system reconnaissance, shell execution, file upload and download, in-memory shellcode loading, sleep masking, and persistence through an HKCU Run key. Command-and-control exclusively uses Microsoft Graph API: Outlook emails carry commands and responses, while OneDrive stores heartbeat messages and transferred files. The content describes two generations, dated October 2025 and December 2025–January 2026.
Previously undocumented Rust backdoor targeting 32-bit and 64-bit Windows systems, used by UAT-11587 for espionage against government and policy organizations across eight Asian countries. It supports reconnaissance, command execution, file transfers, in-memory shellcode execution and persistence. Antino uses Microsoft Graph to poll an attacker-controlled Outlook mailbox every ten seconds, exchanging commands and results as structured JSON in specially formatted email subjects. It uses separate OneDrive folders for stolen files and incoming attacker tools, blending communications into legitimate Microsoft 365 traffic. Targeted phishing initiates a five-stage delivery chain that ultimately sideloads Antino through a signed Microsoft diagnostic binary. The reported campaign involved approximately 350 compromised endpoints.
Previously undocumented Windows backdoor deployed by UAT-11587 through a multistage spear-phishing attack chain and DLL sideloading. It supports reconnaissance, process and directory enumeration, command execution, PowerShell execution, file transfer, in-memory shellcode loading, and persistence. Its command-and-control channel uses Microsoft Graph to access Microsoft 365: Outlook mailbox messages carry commands, polled every 10 seconds, while OneDrive provides heartbeat and file-transfer functions. It also abuses Windows Scripted Diagnostics to execute attacker-controlled PowerShell through legitimate Windows components.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.