Hackers Built a Windows Backdoor Whose Entire C2 Lives Inside Microsoft 365
Antino Windows backdoor routes its entire command-and-control through Microsoft 365, using themed HTA/WSF stagers against Taiwan, Tibet, and Latin America targets.
Analysis documents the Antino Windows backdoor, whose entire C2 channel is hidden inside Microsoft 365 services. Dozens of HTA and WSF stagers use geopolitically themed lures—including CSIS Indo-Pacific, Taiwan information-warfare workshops, TPiE inauguration, Venezuela/Ukraine news, and cross-border repression seminars—to deliver a multi-stage chain. This comprises a Stage 2 JScript downloader/decryptor, encrypted JScript orchestrators, encrypted BinaryFormatter resources, TestAssembly.dll downloaders, and final slc.dll backdoors in Gen 1 and Gen 2 variants plus standalone fake installers.