Analyzing NotDoor: Inside APT28’s Expanding Arsenal
ID: d488c0d5-ff35-5b2a-9302-b5c5e82aef89
STIX ID: report--d488c0d5-ff35-5b2a-9302-b5c5e82aef89
Feed Name: Lab52 Blog
LAB52 (S2 Grupo) describes 'NotDoor', an Outlook VBA backdoor attributed to APT28 that is deployed via DLL side‑loading of a signed OneDrive.exe. The backdoor installs a VBA project (VbaProject.OTM), disables macro/security dialogs, monitors incoming emails for configured trigger strings (e.g., "Daily Report"), and supports commands to exfiltrate files, upload files, and execute commands; the report includes registry persistence details, obfuscation/encoding methods, and IOCs (file hashes, paths, and an exfiltration email).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
