Analyzing NotDoor: Inside APT28's Expanding Arsenal

Sept. 3, 2025, 8:17 p.m.

Description

LAB52 has identified a new backdoor called NotDoor, attributed to APT28, a Russian intelligence-linked threat group. NotDoor is a VBA macro for Outlook that monitors incoming emails for specific trigger words, enabling data exfiltration, file uploads, and command execution on victim computers. The backdoor is deployed via Microsoft OneDrive.exe using DLL side-loading, and it establishes persistence by modifying registry keys. NotDoor employs obfuscation techniques and a custom string encoding method. It can execute commands, exfiltrate files, and upload files to the victim's machine. The malware demonstrates APT28's continuous evolution in bypassing defense mechanisms, posing a significant threat to NATO member countries across various sectors.

Date

  • Created: Sept. 3, 2025, 5:31 p.m.
  • Published: Sept. 3, 2025, 5:31 p.m.
  • Modified: Sept. 3, 2025, 8:17 p.m.

Indicators

  • 8f4bca3c62268fff0458322d111a511e0bcfba255d5ab78c45973bd293379901
  • 5a88a15a1d764e635462f78a0cd958b17e6d22c716740febc114a408eef66705

Attack Patterns