Threats Tagged 'registry modification'
View all threats tagged with 'registry modification'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'registry modification'
Click on any threat for detailed analysis and mitigation recommendations
NotDoor is a backdoor malware leveraging Outlook macros for persistence and lateral movement within compromised environments. It stages files in C:\ProgramData and abuses DLL sideloading via OneDrive.exe to evade detection. The malware executes encoded PowerShell commands, modifies registry keys to enable macros and disable security dialogs, and uses Outlook functions for command-and-control (C2) communication and email monitoring. Detection strategies include monitoring suspicious PowerShell activity, registry changes, and the creation of VbaProject. OTM files by non-Outlook processes. The threat is linked to the APT28 (Fancy Bear) actor and represents a medium-severity risk. European organizations using Microsoft Outlook and OneDrive are potential targets, especially those in critical infrastructure and government sectors. Mitigation requires focused monitoring, macro policy enforcement, and DLL sideloading prevention measures. Join the discussion | AlienVault OTX General | 11/15/2025, 04:44:45 UTC Added: 11/17/2025, 09:32:29 UTC |
Showing 1 to 1 of 1 result