Threats Tagged 'notdoor'
View all threats tagged with 'notdoor'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'notdoor'
Click on any threat for detailed analysis and mitigation recommendations
NotDoor is a backdoor malware leveraging Outlook macros for persistence and lateral movement within compromised environments. It stages files in C:\ProgramData and abuses DLL sideloading via OneDrive.exe to evade detection. The malware executes encoded PowerShell commands, modifies registry keys to enable macros and disable security dialogs, and uses Outlook functions for command-and-control (C2) communication and email monitoring. Detection strategies include monitoring suspicious PowerShell activity, registry changes, and the creation of VbaProject. OTM files by non-Outlook processes. The threat is linked to the APT28 (Fancy Bear) actor and represents a medium-severity risk. European organizations using Microsoft Outlook and OneDrive are potential targets, especially those in critical infrastructure and government sectors. Mitigation requires focused monitoring, macro policy enforcement, and DLL sideloading prevention measures. Join the discussion | AlienVault OTX General | 11/15/2025, 04:44:45 UTC Added: 11/17/2025, 09:32:29 UTC |
LAB52 has identified a new backdoor called NotDoor, attributed to APT28, a Russian intelligence-linked threat group. NotDoor is a VBA macro for Outlook that monitors incoming emails for specific trigger words, enabling data exfiltration, file uploads, and command execution on victim computers. The backdoor is deployed via Microsoft OneDrive.exe using DLL side-loading, and it establishes persistence by modifying registry keys. NotDoor employs obfuscation techniques and a custom string encoding method. It can execute commands, exfiltrate files, and upload files to the victim's machine. The malware demonstrates APT28's continuous evolution in bypassing defense mechanisms, posing a significant threat to NATO member countries across various sectors. Join the discussion | AlienVault OTX General | 09/03/2025, 17:31:14 UTC Added: 09/03/2025, 19:47:48 UTC |
Showing 1 to 2 of 2 results