Antino is a custom Windows backdoor associated with the China-linked threat actor Jewelbug, also tracked as Earth Alux, REF7707, Ink Dragon, and CL-STA-0049. It has been used in cyber-espionage operations targeting government, military, police, telecommunications, and related communications environments across the Middle East, Southeast Asia, South Asia, and likely Taiwan. Antino has also appeared within the same broader operational ecosystem that supported Jewelbug’s financially motivated cryptocurrency fraud activity.
Antino is used as Jewelbug’s primary Windows implant and is commonly deployed after browser-focused victim selection or lure-based delivery. Observed infection vectors include malicious HTML Application downloaders themed around current geopolitical events, as well as fake Adobe Flash and bogus software installer prompts shown to selected victims during watering-hole activity on compromised webmail infrastructure. In major campaigns, victims were first profiled through injected browser-side code and then presented with a fake update prompt that delivered Antino to Windows systems.
Once executed, Antino functions as a backdoor that provides remote access and supports follow-on payload deployment. A notable characteristic is its use of the Microsoft Graph API for command and control, allowing its traffic to blend with legitimate Microsoft cloud service activity and complicate detection. Antino has been used in conjunction with Jewelbug’s broader XG-Web framework and paired with malicious browser tooling, including the PDF Viewer extension, to combine host-level access with browser surveillance and data theft. Through this ecosystem, operators were able to steal cookies, credentials, email content, and other sensitive user data while maintaining covert access to victim environments.
Antino is best understood as part of a multi-platform intrusion set in which Windows compromise, browser compromise, and downstream access expansion are tightly integrated. Its operational role is consistent with post-compromise espionage, persistence, and defense-evasion objectives in targeted intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Antino, a Windows backdoor that's delivered via malicious HTML Application (HTA) downloaders centered around current geopolitical events, as well as bogus Adobe Flash or Adobe installer from threat actor-controlled domains.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
"the malicious code activating on the login page and every mailbox view to exfiltrate cookies over a WebSocket connection and serve a next-stage payload" | "a web hosting provider was compromised to inject JavaScript code into a common webmail installation used by multiple ministries associated with a Middle Eastern government. The watering hole campaign spanned 15 government webmail tenants"
The researchers explained that the threat actor obtained write access to the webmail installation used by multiple government ministries and agencies after compromising a shared web-hosting platform operated by the state telecommunications provider and national services agency.
The extension talked to a Windows helper registered as a native-messaging host under the misleading name com.microsoft.runedge, which ran operator commands through the Windows command interpreter and returned the output to the panel.
It also sideloaded the “PDF Viewer” extension into the victim's browser profile, dropped the native-messaging helper, and wrote the registry value that enabled it: HKCU\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.microsoft.runedge
Valuable targets would receive a fake Adobe Flash update prompt, which installs the main payload on Windows, the Antino backdoor, and browser tooling.
"Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control channel..."
"Upon execution, the malware uses the Microsoft Graph API for C&C to evade detection and blend in with normal traffic."
Once running, Antino uses the Microsoft Graph API as its C&C channel, hiding its traffic inside legitimate Microsoft cloud services... the backend created a public Google Document, wrote an obfuscated payload into the body, and had implants fetch the documents and execute the payloads.
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows backdoor delivered via HTA downloaders and fake Adobe installers; it uses the Microsoft Graph API for command-and-control to blend with normal traffic and is delivered as a second-stage payload in the campaign.
A Windows backdoor used across multiple Jewelbug campaigns. It communicates through the Microsoft Graph API to blend malicious traffic with legitimate Microsoft cloud activity and was deployed through fake software installers and themed lures.
A custom Windows backdoor used by Jewelbug as one of its primary malware implants.
A Windows backdoor delivered via malicious HTA files and fake Adobe Flash/Adobe installers, used by Jewelbug to establish access and deploy additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.