logo

ncsc-mar-authentic_antics.pdf

ID: 3a5be3d5-d064-4b09-a342-baca2237502f

STIX ID: report--3a5be3d5-d064-4b09-a342-baca2237502f

Threat Score

75/100

Uploaded: 2026-08-11

Published Date: 2025-06-16

Last Modified Date: 2025-06-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
AUTHENTIC ANTICS is a targeted credential- and OAuth2 token-stealing malware that runs inside the Outlook process to display malicious login prompts, intercept authorization codes, redeem tokens, and exfiltrate compressed and RSA-encrypted credential/token data by sending emails through the victim's Outlook web API (with SaveToSentItems=false). The loader (Microsoft.Identity64.dll) uses environmental keying (machine GUID and volume serial), unhooks ntdll registry APIs and hooks iertutil.dll, persists via COM hijacking, includes MSAL .NET code to appear legitimate, and uses registry locations for staging and token caching; multiple YARA detection rules and IOCs (registry keys) are provided.