ncsc-mar-authentic_antics.pdf
ID: 3a5be3d5-d064-4b09-a342-baca2237502f
STIX ID: report--3a5be3d5-d064-4b09-a342-baca2237502f
Threat Score
75/100
Uploaded: 2026-08-11
Published Date: 2025-06-16
Last Modified Date: 2025-06-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
AUTHENTIC ANTICS is a targeted credential- and OAuth2 token-stealing malware that runs inside the Outlook process to display malicious login prompts, intercept authorization codes, redeem tokens, and exfiltrate compressed and RSA-encrypted credential/token data by sending emails through the victim's Outlook web API (with SaveToSentItems=false). The loader (Microsoft.Identity64.dll) uses environmental keying (machine GUID and volume serial), unhooks ntdll registry APIs and hooks iertutil.dll, persists via COM hijacking, includes MSAL .NET code to appear legitimate, and uses registry locations for staging and token caching; multiple YARA detection rules and IOCs (registry keys) are provided.
