ANTINO

ANTINOAntino

Description

According to Symantec, Antino is the Windows backdoor used by the Jewelbug (aka REF7707, Earth Alux, CL-STA-0049) group. It is delivered by HTA downloaders themed on current geopolitical events, and as fake Adobe Flash or Adobe installers (file names such as flashcenter_pp_ax_install_en.exe and Adobeinstall.exe) hosted on group-controlled domains. Once running, it uses the Microsoft Graph API as its command-and-control channel, hiding its traffic inside legitimate Microsoft cloud services. It also sideloads a malicious 'PDF Viewer' browser extension into the victim's browser profile and drops a native-messaging helper registered as com.microsoft.runedge, which runs operator commands through the Windows command interpreter. Note that most antivirus engines label samples of this family as Fsysna, Midie or CRAITHNEX; Antino is the Symantec name.
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.