logo

Analyzing NotDoor: Inside APT28’s Expanding Arsenal

ID: d488c0d5-ff35-5b2a-9302-b5c5e82aef89

STIX ID: report--d488c0d5-ff35-5b2a-9302-b5c5e82aef89

Feed Name: Lab52 Blog

Threat Score
90/100

Date Published: 2025-09-03

Date Updated: 2026-04-28

Author: 3722304989

...
...

LAB52 (S2 Grupo) describes 'NotDoor', an Outlook VBA backdoor attributed to APT28 that is deployed via DLL side‑loading of a signed OneDrive.exe. The backdoor installs a VBA project (VbaProject.OTM), disables macro/security dialogs, monitors incoming emails for configured trigger strings (e.g., "Daily Report"), and supports commands to exfiltrate files, upload files, and execute commands; the report includes registry persistence details, obfuscation/encoding methods, and IOCs (file hashes, paths, and an exfiltration email).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.