P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Antino polls an Outlook mailbox every 10 seconds, over Microsoft hostnames enterprises commonly allow

Cisco Talos says the China-nexus backdoor Antino takes its orders from an Outlook mailbox every 10 seconds through Microsoft Graph. The report names no UK victim, no tenant and no application ID, so the useful question is which of your controls can see it.

By Parminder Kumar Sharma · · 19 min read

A dark desk at night with an open laptop whose screen shows a mailbox drawn as blank rounded rows, one outlined in cyan, beside a grid of six blank file tiles, with a closed plain grey document folder lying in front of it.

Seven requests a minute to two Microsoft hostnames

Take the two intervals Cisco Talos gives for the Antino backdoor and do the sums. It reads its Outlook mailbox every 10 seconds, which is six reads a minute, and it writes a OneDrive heartbeat every minute, which is one more. That is seven requests a minute and 10,080 a day from one implant that stays switched on (derived: 6 + 1 = 7, times 1,440 minutes; it assumes the one-minute OneDrive heartbeat Talos describes and ignores token requests). Every one goes to Microsoft Graph. Talos says the connections end at two hostnames, graph.microsoft.com and login.microsoftonline.com, that are “widely trusted and commonly allowed in enterprise environments”.

What that arithmetic does not establish is that your network, your tenant or any UK organisation is involved. Talos describes the mailbox folder and the OneDrive as the threat actor’s own. It does not say which Microsoft 365 tenant holds the Entra application the implant signs in as, and its indicator list contains no application ID, tenant ID or mailbox address. It names no UK victim. It counts at least 16 institutions in eight countries, of which 10 are confirmed.

So the question for a UK security lead is narrower than the headline. If the orders arrive in someone else’s mailbox, over a hostname your network probably already allows, which of your controls can see them? Several of the controls usually listed for Microsoft 365 abuse do not fit this channel as Talos describes it. One control does look past the hostname: Microsoft documents tenant restrictions v2 as blocking a service principal’s sign-in to a tenant you have not approved. This briefing says which controls fit, and puts them in order.

Who said what, and when

Cisco Talos published on Wednesday 30 September 2026. The page shows 06:00 and its own metadata says 10:00 UTC, which is 11:00 BST. The author is Ashley Shen. The Hacker News (Ravie Lakshmanan) published at 18:33 BST on Friday 2 October, about two days later, and links to the report. Where the two differ, this briefing follows Talos.

Where The Hacker News and the Talos report differ. Both pages were read in full on 3 October 2026.

  1. Point
    When it began
    The Hacker News
    First detected in September 2025 in a spear-phishing campaign against Taiwan’s policy community.
    Cisco Talos
    First observed in September 2025, with Philippines-themed lures. The Taiwan campaign that began the investigation was in March 2026.
  2. Point
    Rust build paths
    The Hacker News
    Nearly a dozen builds cite rsproxy.cn.
    Cisco Talos
    Ten distinct build outputs.
  3. Point
    Countries
    The Hacker News
    Lists seven, puts Syria “beyond Asia”, and still says eight Asian countries.
    Cisco Talos
    Eight, counting Syria: Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria.
  4. Point
    Email checks
    The Hacker News
    Spoofed senders got past SPF and DMARC.
    Cisco Talos
    SPF passed for the attacker’s own domain, DMARC failed, and the message was delivered because the impersonated domain’s policy was none.
  5. Point
    Novelty
    The Hacker News
    A previously undocumented backdoor.
    Cisco Talos
    Uses that phrase, and notes Symantec published on Jewelbug while the report was being prepared.

The Symantec point is the one that changes the reading. Symantec’s Threat Hunter Team, part of Broadcom, published on 13 August 2026, which is 48 days before Talos (derived). It calls Antino the main implant of a China-based hackers-for-hire group it tracks as Jewelbug, says Antino uses the Microsoft Graph API as its command channel, and lists 23 file hashes. Ten of them are also in Talos’s list of 63 (derived), and three exact URLs match, so the two vendors are describing the same malware and some of the same infrastructure. They differ on what sort of actor sits behind it, which the attribution section covers.

Stated and not stated

This table sets what Talos publishes against what a defender needs. The right-hand column is the one to read twice.

Stated and not stated in the Cisco Talos report of 30 September 2026. Where a cell cites Symantec, it says so.

  1. Question
    Who, and how sure
    Stated
    UAT-11587. China-nexus, high confidence. Purpose is intelligence gathering, moderate confidence.
    Not stated
    Who employs the operators. Any link to Jewelbug’s fraud business: Talos could not verify one.
  2. Question
    Targets
    Stated
    Public-sector and national-security-adjacent bodies in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria (moderate to high confidence). Sectors include defence, foreign affairs, legislatures, think tanks, universities and civil society.
    Not stated
    Any victim name. Any UK or European target. Which sector each of the 16 sits in.
  3. Question
    Scale
    Stated
    At least 16 environments: 10 confirmed, 5 probable, 1 intended target. About 350 compromised endpoints.
    Not stated
    How endpoints were counted, how many an operator drove, what was taken.
  4. Question
    Dates
    Stated
    First observed September 2025. Antino builds from October 2025 (Gen1) and December 2025 to January 2026 (Gen2). Largest wave 8 and 9 June 2026, about 57 endpoints. Activity seen through July 2026.
    Not stated
    When Antino first ran on a victim. Dwell time. Whether the activity has stopped.
  5. Question
    Initial access
    Stated
    Spoofed spear-phishing, a redrawn Gmail attachment card, a five-stage chain. A separate fake-installer branch.
    Not stated
    How the fake-installer branch reached victims. Symantec describes a planted script on a Middle Eastern government webmail platform.
  6. Question
    Command channel
    Stated
    Microsoft Graph. Outlook for orders every 10 seconds, OneDrive for heartbeat and files. Gen2 signs in as a registered Entra ID application with the client-credentials flow, with no user sign-in.
    Not stated
    Whose tenant holds the application. Application ID, tenant ID, mailbox address, credential type. How Gen1 signed in. Whether large transfers touch other hostnames.
  7. Question
    Persistence
    Stated
    A Run value under the current user, a staging folder, PowerShell run through the Windows Scripted Diagnostics framework.
    Not stated
    Whether the operator keeps other access.
  8. Question
    Microsoft’s response
    Stated
    No statement.
    Not stated
    Whether Microsoft disabled the application, mailbox or tenant, or told victims.
  9. Question
    Detection advice
    Stated
    21 ClamAV signatures, three Snort rule IDs, a .NET assembly GUID, 63 hashes, 18 network indicators, 68 URLs.
    Not stated
    Any hunt guidance for Graph, Entra or Exchange logs. Any mailbox rule or folder anomaly to look for in a victim tenant: the mailbox is the actor’s. Any hardening advice.
  10. Question
    The UK
    Stated
    No mention.
    Not stated
    Any UK victim, recipient, lure or target.

How the channel works, at the level a defender needs

Delivery starts with a spoofed email and ends with a signed Windows ADK binary, GatherOsState.exe, loading a DLL called slc.dll that sits beside it. That DLL is Antino, a Rust backdoor built in 32-bit and 64-bit versions. Talos numbers the chain as five stages, and the diagram puts each one beside the trusted name it borrows.

A vertical chain of six boxes drawn from the Cisco Talos report. A spoofed email that passed SPF but failed DMARC on a domain whose policy was none, then five stages: an HTA or WSF stager from Cloudflare Pages, a JScript downloader using Cloudflare R2 or Amazon CloudFront, a dot-NET chain inside mshta.exe, a downloader that launches a signed Windows ADK binary, and DLL sideloading of Antino, which polls Microsoft Graph. A right column names the trusted name each step borrows.
Drawn from the Cisco Talos report of 30 September 2026. The stage numbers are Talos’s; the email row is added.

Talos says Antino’s “native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive”. Two mechanisms do the work.

OneDrive carries the heartbeat and the files. Three folders are named from the operator’s side: one the implant writes a heartbeat file into, one for data the operator takes from the victim, and one for tools the operator sends in. The heartbeat goes up on first run and again every minute. It holds a session ID, a timestamp, an online or offline flag, the machine name, the username, the platform and a campaign code. Talos says classic Gen1 builds used email drafts for sessions and heartbeats, so this describes the later builds.

Outlook carries the orders. Every 10 seconds the implant reads a folder in the actor’s mailbox for messages whose subject begins command_req_ followed by its session ID. Its results go back as messages beginning command_res_. The body of an order names a command and its parameters. On the wire that is an HTTPS request to graph.microsoft.com for the messages in a named mailbox, filtered on that subject and carrying a bearer token; Talos shows one in its Figure 18, with the mailbox redacted.

The newer generation, Gen2, signs in with the OAuth 2.0 client-credentials flow as a registered Entra ID application, which Talos says needs no interactive user sign-in. Three points from Microsoft’s documentation matter for what follows. The token request goes to login.microsoftonline.com and names the tenant it is for. App-only access to Graph rests on application permissions, and those always require administrator consent. And the credential behind the flow can be a client secret, a certificate or a federated credential. Talos does not say which Antino holds, and does not say how Gen1 signed in.

Ten command handlers are listed across the builds. They cover cmd.exe and PowerShell execution, host information, directory listing, file transfer in both directions, running an operator-supplied program, in-memory shellcode loading, a persistence command and an exit command. One option hides loaded shellcode from memory scanners while it sleeps. Persistence is routed through a Microsoft-signed diagnostic workflow, which Talos says can make the activity harder to attribute to the implant, although it “does not eliminate observable PowerShell, file-creation or Registry telemetry”.

A trusted name is not a control

Every step in the diagram wears a name that controls are built to trust: a sender that looks like the organisation, Cloudflare, Amazon, a Windows component, a Microsoft signature. The last is the one that matters most to defenders, because Talos says its hostnames are widely trusted and commonly allowed. An allow-list entry for graph.microsoft.com is a statement about a destination. It says nothing about whose tenant a request is for, which application is asking, or which program on the host sent it. The same two hostnames serve ordinary Microsoft 365 sign-in and Graph requests, which is why Talos says the channel blends in at the network layer.

This is not a Microsoft problem alone. Symantec reports the same group running a second command route through public Google Documents, which Symantec says resolves to Google-owned infrastructure unlikely to be blocked by reputation filtering. The failure is treating a well-known name as a verdict.

Top row, left to right: an infected Windows host, Microsoft’s login and Graph endpoints, and the Outlook mailbox and OneDrive folders Talos calls the threat actor’s. A dashed box for your own tenant sits outside the path. Bottom row, four controls: a domain allow-list sees only an allowed name, tenant logs and workload identity policy are probably blind, TLS inspection could see the mailbox request if it decrypts, and process-level egress telemetry on the host is the best fit.
The path is from the Cisco Talos report. The four control cards are this briefing’s reading; each is tagged stated or inference.

Controls checked against the channel as Talos describes it. The ratings are this briefing’s reading, not Talos’s. Microsoft statements are from Microsoft Learn.

  1. Control
    Allow-list for Microsoft hostnames
    Fits this channel?
    No
    Why
    It permits the destination Talos names and cannot tell this caller from any other.
  2. Control
    Conditional Access for workload identities
    Fits this channel?
    Probably not
    Why
    Microsoft says it applies to single-tenant service principals registered in your tenant, and needs Workload Identities Premium licences. Talos does not place the application in a customer tenant.
  3. Control
    Entra audit logs and Microsoft Graph activity logs
    Fits this channel?
    Probably not here
    Why
    Microsoft says they record changes and requests in your tenant. Keep them on: a hit in yours would be new information.
  4. Control
    Tenant restrictions v2
    Fits this channel?
    Yes, if signalled
    Why
    Microsoft says it blocks a service principal’s sign-in to a tenant you have not allowed, and shows a client-secret sign-in failing as its example. It acts only if the request carries the signal: a proxy that decrypts and adds a header, Global Secure Access, or Windows policy for apps on the Windows networking stack. Talos does not say how Antino reaches the network.
  5. Control
    Process-level egress telemetry on endpoints
    Fits this channel?
    Yes
    Why
    It asks which program called Graph, whoever owns the tenant. A decrypting proxy can also log the Graph request Talos shows.
  6. Control
    Blocking mshta.exe and script-host content from the internet; application control
    Fits this channel?
    Yes
    Why
    Acts before Antino is on the host. The stagers run in mshta.exe or Windows Script Host, and a signed binary loads the backdoor from a writable folder.
  7. Control
    DMARC enforcement and handling of DMARC fails
    Fits this channel?
    Yes, for delivery
    Why
    SPF passed, DMARC failed, and delivery followed because the impersonated domain’s policy was none.

Rows two and three are controls on your own tenant, and the channel Talos describes runs in somebody else’s. That is an inference from Talos’s wording, not a statement in the report, and it would change if Talos or Microsoft said the application sat in a victim tenant. Tenant restrictions v2 is different because it keys on the tenant a token request is for, so it does not depend on who owns the application. That is the practical meaning of the friendly-name point: an allow-list should name tenants, not hostnames.

The attribution, as the vendor assesses it

Method first, accusation second. Talos says it assesses UAT-11587 as China-nexus with high confidence, “based on the totality of corroborating technical and operational evidence, rather than any single indicator”. The examples it gives are a zh-CN language tag, a Simplified Chinese author value and +08:00 timestamps in a decoy document and in both recovered phishing emails; Cargo registry paths for rsproxy.cn, a Rust package mirror for mainland China, in ten builds; and lures on Taiwanese politics, civil defence, maritime, diplomatic and security themes. Talos qualifies two of these itself: UTC+8 covers many places, and the mirror’s public availability does not reveal where a developer sits.

Assessments in the Talos report, with the confidence Talos states for each.

  1. Assessment
    UAT-11587 is China-nexus
    Confidence stated
    High
    Basis given
    The totality of technical and operational evidence, not one indicator.
  2. Assessment
    Its purpose is intelligence gathering
    Confidence stated
    Moderate
    Basis given
    Sustained government and national-security targeting, tailored political and diplomatic lures, capabilities for persistent access and information collection.
  3. Assessment
    Eight countries were targeted
    Confidence stated
    Moderate to high
    Basis given
    The available evidence, which the report does not break down by country.
  4. Assessment
    Shared CloudFront distribution with UNC6384
    Confidence stated
    Low
    Basis given
    Infrastructure can be reused, and the two campaigns used different malware and command architectures.
  5. Assessment
    Overlap with Jewelbug
    Confidence stated
    Overlaps found; fraud link not verified
    Basis given
    Talos tracks UAT-11587 separately because it could not verify a link to the financially motivated activity.

“China-nexus” is a vendor’s label for a connection to China. It is not a finding about who employs the operators, and Symantec’s reading shows why the difference matters. Symantec assesses Jewelbug as a China-based hack-for-hire group that runs espionage and a cryptocurrency fraud business from one control panel. It says the SEO business most likely supplied access, delivery and infrastructure to the espionage side, and that the precise relationship “is not fully established”. Talos says it could not independently verify that connection.

Both are vendors with products to sell. Talos is Cisco’s threat intelligence group, and its report closes with an Integrated Coverage block for web, DNS, malware and email security and points to a Cisco data sheet. Symantec sits inside Broadcom. That is a reason to read the confidence labels closely, not a reason to discount the reports: the indicators are checkable whoever publishes them.

The UK angle: none named, an audience that fits

Plainly: the report names no UK organisation, no UK recipient and no UK-linked target. A search of its full text for the United Kingdom, Britain, British, Europe and London finds nothing. The Hacker News mentions European diplomatic and government targets only when describing an earlier campaign by a different cluster, UNC6384, whose link to UAT-11587 Talos rates low confidence.

The audience profile is another matter. Talos’s sector list includes foreign affairs and diplomatic services, think tanks, universities and research institutions, and civil society, human rights and public policy organisations. Those categories exist in the UK. Whether any UK recipient received a lure is not stated, and where recipient details were unavailable Talos says its audience assessments rest on file names and subject matter and “do not confirm delivery or compromise”.

The lures borrow the calendar of policy work: a decoy titled as the CSIS Indo-Pacific Forecast 2026 event details, a cross-border repression seminar agenda, proceedings of a Tehran bilateral summit, and a legislators’ tax ruling copied from Taiwan’s Ministry of Finance. A UK team that follows Asian politics receives invitations like these legitimately every week, which is why they work (our inference). Earlier briefings cover neighbouring patterns: a China-aligned group’s fake AI committee invitations to US policy experts, event invitations used by the Russia-linked Star Blizzard, and MI5’s alert about UK-linked academics and projects funded by China’s civilian intelligence service. For service accounts with no human owner, which are the quiet end of the same Microsoft 365 surface, see the TeamFiltration brief.

What the report gives you to hunt with

Talos publishes 63 SHA-256 hashes, 18 network indicators (17 domains and one IP address) and 68 URLs, which add up to the 149 lines in its indicator file (derived). It adds 21 ClamAV signatures and three Snort rule IDs. Only 12 of the 63 hashes are the backdoor itself; the other 51 are delivery stages such as stagers, downloaders and encrypted resources (derived from Talos’s labels). A hash search therefore finds a chain that has already been used, and it cannot show the channel. The more durable markers are behavioural, and Talos names several: a signed ADK binary beside a DLL it should not have, a staging folder, a Run value, and the diagnostic host launched with its embedding switch. The bundle’s file extensions are random, so a filter on .dll or .exe misses it.

Sender (envelope) domain:      osc-cdn[.]com
Fake-installer delivery:       microsoft-flash[.]com, wps-cn[.]com
Pages tracking host:           oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev
Signed host and its DLL:       GatherOsState.exe with slc.dll beside it
Staging folder:                %LOCALAPPDATA%\Windows GatherOSStateKit\
Diagnostics host launch:       sdiagnhost.exe -Embedding (working copy under C:\Windows\Temp\SDIAG_ plus a GUID)
.NET downloader marker:        assembly GUID b2b3adb0-1669-4b94-86cb-6dd682ddbea3
Antino Gen2 slc.dll (SHA-256): 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff
Graph-calling standalone:      0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd

What to do, in the order worth doing it

The report contains no hardening advice. The order below is this briefing’s, built from the report’s facts and from Microsoft’s and the NCSC’s documentation. It puts the controls that fit this channel before the ones that do not.

Take this with you

For UK organisations that work with or in Asian government and policy circles

  • Decide whether you are in the audience. List the staff, partners and projects that deal with think tanks, universities, civil society, diplomatic or government bodies in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar or Syria. The report names no UK target, so this sets where to look first, not whether you were hit.
  • Search endpoint telemetry first, because the channel is hidden and the host is not. Look for GatherOsState.exe running from a user-writable folder with slc.dll beside it, a folder named Windows GatherOSStateKit under local app data, a Run value under the current user that points there, and sdiagnhost.exe started with its embedding switch by an unexpected parent. Talos says the diagnostic workflow does not eliminate PowerShell, file-creation or registry telemetry.
  • List every process on your estate that connects to graph.microsoft.com or login.microsoftonline.com. Expect Office, Teams, OneDrive, your browsers and your management agents. A signed Windows ADK binary, an executable in a user profile or temporary folder, or mshta.exe is not. Look for connections at fixed 10 second and 60 second intervals, and for near-regular timing as well, because the report does not say whether the interval is jittered. This hunt is ours, not Talos’s.
  • Put tenants, not hostnames, on the allow list. Tenant restrictions v2 is the documented control that keys on the tenant a token request is for, and Microsoft says it blocks a service principal’s sign-in to a tenant you have not allowed. It works only if the request carries the signal: a proxy that decrypts login.microsoftonline.com traffic and adds the header, Global Secure Access, or Windows policy, which covers apps on the Windows networking stack. For the Windows policy route, Microsoft says to block apps that cannot carry the signal, such as Chrome and Firefox, with App Control or the Windows firewall. Talos does not say how Antino reaches the network, so test from a lab device with a client that brings its own network stack, and record the result.
  • Search mail and web logs for the delivery layer: osc-cdn[.]com as an envelope sender, the ten pages.dev delivery addresses and the r2.dev and CloudFront hosts Talos lists, and the rest of its 18 network indicators. Alert on mshta.exe or Windows Script Host making any network connection at all.
  • Run one cheap search in your own tenant: mail whose subject begins command_req_ or command_res_. Talos places those messages in the actor’s mailbox, so a hit in yours would be new information and should go to your vendor and to Microsoft.
  • Block the start of the chain where nobody needs it. Stop mshta.exe and Windows Script Host running downloaded HTA and WSF files for ordinary users, and use application control so signed binaries cannot run from user-writable folders. The chain depends on both.
  • Keep the tenant-side controls for their own sake and do not mistake them for cover here. Review new app registrations, service principals and consent grants in the Entra audit log, turn on Microsoft Graph activity logs if you hold Entra ID P1 or P2, and apply Conditional Access for workload identities to your own single-tenant service principals. Microsoft says these cover your tenant, and the last applies only to service principals registered in it.
  • Fix your own domains’ DMARC. The spoofing worked because the impersonated domain asked recipients only to monitor. Move to a policy of reject using the NCSC’s staged guidance, which calls reject on all your domains “the best way to prevent spoofing of your email”, and ask your mail provider how it treats a message whose visible From domain fails DMARC when that domain publishes none.
  • Tell your Asia-facing staff and partners that policy-event invitations are the lure, including ones that arrive on personal Gmail, where the cloned attachment card is built to render.
  • Write down what you cannot answer. How far back do your endpoint and proxy logs reach? Talos first observed the activity in September 2025, more than 12 months before today.

What we could not verify

The question this leaves

If one machine on your network made 10,080 requests a day to graph.microsoft.com from a program that is not Office, who would be asked which program it was, and which log would tell them?

Key facts

Sources

  1. PrimaryChina-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor, by Ashley Shen, 30 September 2026. The primary report; read in full, including its figures and indicator list.Cisco Talosaccessed 2026-10-03
  2. PrimaryTalos’s indicator file for the report, linked from it; read as raw text and compared line by line with the indicator list in the report.Cisco Talosaccessed 2026-10-03
  3. PrimaryJewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side, Threat Hunter Team, 13 August 2026. Names Antino as Jewelbug’s main implant; read in full.Symantec and Carbon Black (Broadcom)accessed 2026-10-03
  4. PrimaryConditional Access for workload identities. Used for what the control covers: single-tenant service principals registered in your tenant, and the licence it needs.Microsoft Learnaccessed 2026-10-03
  5. PrimaryGet access without a user (Microsoft Graph app-only access). Used for application permissions, administrator consent and the credential types the client-credentials flow accepts.Microsoft Learnaccessed 2026-10-03
  6. PrimarySet up tenant restrictions v2. Used for what the control is documented to do, including its section on service principals, and for how it must be signalled.Microsoft Learnaccessed 2026-10-03
  7. PrimaryMicrosoft Graph activity logs. Used for what they record (requests Graph processes for a tenant) and the licence they need.Microsoft Learnaccessed 2026-10-03
  8. PrimaryMicrosoft Entra audit logs. Used for the statement that changes to applications and service principals are captured.Microsoft Learnaccessed 2026-10-03
  9. PrimaryEmail security and anti-spoofing, step 5: reject spoof emails. Used for the NCSC’s position that a DMARC policy of reject on all domains is the best way to prevent spoofing.National Cyber Security Centreaccessed 2026-10-03
  10. Reported byAntino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign, by Ravie Lakshmanan, 2 October 2026. The pointer to Talos; where it differs from Talos, this briefing follows Talos.The Hacker Newsaccessed 2026-10-03

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.