Antino is a custom Windows backdoor associated with the China-linked threat actor Jewelbug, also tracked as Earth Alux, REF7707, Ink Dragon, and CL-STA-0049. It has been used in cyber-espionage operations targeting government, military, police, telecommunications, and related communications environments across the Middle East, Southeast Asia, South Asia, and likely Taiwan. Antino has also appeared within the same broader operational ecosystem that supported Jewelbug’s financially motivated cryptocurrency fraud activity.
Antino is used as Jewelbug’s primary Windows implant and is commonly deployed after browser-focused victim selection or lure-based delivery. Observed infection vectors include malicious HTML Application downloaders themed around current geopolitical events, as well as fake Adobe Flash and bogus software installer prompts shown to selected victims during watering-hole activity on compromised webmail infrastructure. In major campaigns, victims were first profiled through injected browser-side code and then presented with a fake update prompt that delivered Antino to Windows systems.
Once executed, Antino functions as a backdoor that provides remote access and supports follow-on payload deployment. A notable characteristic is its use of the Microsoft Graph API for command and control, allowing its traffic to blend with legitimate Microsoft cloud service activity and complicate detection. Antino has been used in conjunction with Jewelbug’s broader XG-Web framework and paired with malicious browser tooling, including the PDF Viewer extension, to combine host-level access with browser surveillance and data theft. Through this ecosystem, operators were able to steal cookies, credentials, email content, and other sensitive user data while maintaining covert access to victim environments.
Antino is best understood as part of a multi-platform intrusion set in which Windows compromise, browser compromise, and downstream access expansion are tightly integrated. Its operational role is consistent with post-compromise espionage, persistence, and defense-evasion objectives in targeted intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence. Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.
Antino, a Windows backdoor that's delivered via malicious HTML Application (HTA) downloaders centered around current geopolitical events, as well as bogus Adobe Flash or Adobe installer from threat actor-controlled domains.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
"a web hosting provider was compromised to inject JavaScript code into a common webmail installation used by multiple ministries associated with a Middle Eastern government. The watering hole campaign spanned 15 government webmail tenants" | "the malicious code activating on the login page and every mailbox view to exfiltrate cookies over a WebSocket connection and serve a next-stage payload"
The researchers explained that the threat actor obtained write access to the webmail installation used by multiple government ministries and agencies after compromising a shared web-hosting platform operated by the state telecommunications provider and national services agency.
Antino supports a powershell command that runs powershell.exe -Command. It also writes attacker-controlled PowerShell scripts into a Scripted Diagnostics working directory.
Antino supports a cmd command that runs cmd.exe /C and captures output.
HTA-hosted Microsoft JScript retrieved encrypted resources, decrypted them using RC4, and executed the decrypted JScript orchestrator in memory.
The Stage 2 script applies custom Base64 decoding and RC4 decryption to downloaded resources. The actor also used randomized nonstandard file extensions for payload components.
Valuable targets would receive a fake Adobe Flash update prompt, which installs the main payload on Windows, the Antino backdoor, and browser tooling.
The script collected cookies and identified users through government email addresses. It then displayed a fake update prompt only to selected Windows users in targeted domains.
Antino abuses the Windows Scripted Diagnostics framework: sdiageng.dll initializes the PCW package and sdiagnhost.exe executes the attacker-controlled result.ps1 script.
The HTA file was executed by mshta.exe; the second-stage JScript was loaded in-process by mshta.exe through the HTA stager.
Antino heartbeat files contain host telemetry including machine name, username, platform, timestamp, and session state; its system_info command collects host and process context.
"Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control channel..."
Outbound Antino connections terminate at graph.microsoft.com and login.microsoftonline.com, and the implant uses the Microsoft Graph API.
Once running, Antino uses the Microsoft Graph API as its C&C channel, hiding its traffic inside legitimate Microsoft cloud services... the backend created a public Google Document, wrote an obfuscated payload into the body, and had implants fetch the documents and execute the payloads.
Antino communicates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive as dead-drop C2 channels.
180 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-compiled Windows espionage backdoor, observed as both standalone executables and sideloaded DLLs. It uses Microsoft Graph APIs and attacker-controlled Outlook and OneDrive resources as dead-drop C2 for host registration, recurring heartbeats, command polling, command output, file transfer, and exfiltration. It supports CMD and PowerShell execution, host/process discovery, file listing and transfer, execution of programs or in-memory shellcode, Registry Run-key persistence, sleep masking for loaded payloads, and abuse of the Windows Scripted Diagnostics workflow to proxy PowerShell execution and persistence actions.
A Windows backdoor delivered via HTA downloaders and fake Adobe installers; it uses the Microsoft Graph API for command-and-control to blend with normal traffic and is delivered as a second-stage payload in the campaign.
A Windows backdoor used across multiple Jewelbug campaigns. It communicates through the Microsoft Graph API to blend malicious traffic with legitimate Microsoft cloud activity and was deployed through fake software installers and themed lures.
A custom Windows backdoor used by Jewelbug as one of its primary malware implants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.