{"id":6333,"date":"2025-09-05T05:33:25","date_gmt":"2025-09-05T05:33:25","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=6333"},"modified":"2025-09-05T05:33:25","modified_gmt":"2025-09-05T05:33:25","slug":"russian-apt28-deploys-notdoor-outlook-backdoor-towards-corporations-in-nato-international-locations","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=6333","title":{"rendered":"Russian APT28 Deploys &#8220;NotDoor&#8221; Outlook Backdoor Towards Corporations in NATO International locations"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 04, 2025<\/span><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><\/span><span class=\"p-tags\">Cybersecurity \/ Malware<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgwhgINzgNirXlZNu6uMWQOzSQpkXFX5mDGt1yQPHtO2SlEBL5JhaNL2BjMrAxMYyKDMMML1L21Ke5hal5Cf_Rsc1EuNQtmmYwhdnu9Pv_J873ucjPw0MicZGydASEKUTFJHpMeffntgtwchJ3CXpFCHDPfJk8_AMbE0vgNoq5_bWFWWhqyJ_mHXXT0MJuA\/s728-rw-e365\/email.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgwhgINzgNirXlZNu6uMWQOzSQpkXFX5mDGt1yQPHtO2SlEBL5JhaNL2BjMrAxMYyKDMMML1L21Ke5hal5Cf_Rsc1EuNQtmmYwhdnu9Pv_J873ucjPw0MicZGydASEKUTFJHpMeffntgtwchJ3CXpFCHDPfJk8_AMbE0vgNoq5_bWFWWhqyJ_mHXXT0MJuA\/s728-rw-e365\/email.jpg\" alt=\"\" border=\"0\" data-original-height=\"380\" data-original-width=\"728\"\/><\/a><\/div>\n<p>The Russian state-sponsored hacking group tracked as <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2024\/05\/kremlin-backed-apt28-targets-polish.html\" rel=\"noopener\" target=\"_blank\">APT28<\/a> has been attributed to a brand new Microsoft Outlook backdoor known as <b>NotDoor <\/b>in assaults concentrating on a number of firms from totally different sectors in NATO member international locations.<\/p>\n<p>NotDoor &#8220;is a VBA macro for Outlook designed to observe incoming emails for a selected set off phrase,&#8221; S2 Grupo&#8217;s LAB52 risk intelligence group <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/lab52.io\/blog\/analyzing-notdoor-inside-apt28s-expanding-arsenal\/\" rel=\"noopener\" target=\"_blank\">stated<\/a>. &#8220;When such an e mail is detected, it permits an attacker to exfiltrate information, add information, and execute instructions on the sufferer&#8217;s pc.&#8221;<\/p>\n<p>The artifact will get its identify from using the phrase &#8220;Nothing&#8221; throughout the supply code, the Spanish cybersecurity firm added. The exercise highlights the abuse of Outlook as a stealthy communication, information exfiltration, and malware supply channel.<\/p>\n<p>The precise preliminary entry vector used to ship the malware is presently not identified, however evaluation reveals that it is deployed by way of Microsoft&#8217;s OneDrive executable (&#8220;onedrive.exe&#8221;) utilizing a method known as DLL side-loading.<\/p>\n<p>This results in the execution of a malicious DLL (&#8220;SSPICLI.dll&#8221;), which then installs the VBA backdoor and disables macro safety protections.<\/p>\n<div class=\"dog_two clear\"><center class=\"cf\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.uk\/audit-beyond-2025-3\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Audit and Beyond\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgJBRZ9iHc2Dfn2-r7JxS9Hs4CvfX-Hh653X5ADO_AM8VUIOM9gxZyVwjlC4Prl8VN1KNSkl8txDkNOTbCqPdfT1Uqa4M8d9Ehyphenhyphenax4AHC_DyzBGElLecdaAHanYIGOHEdi1RL8MA7QP46Ds4v8IK8mI2oTMVR8HDzRvdjijP0VAR9P1pp4k7JTJBOi_36kR\/s728-e100\/audit-3.png\" width=\"728\" height=\"91\"\/><\/a><\/center><\/div>\n<p>Particularly, it runs Base64-encoded PowerShell instructions to carry out a sequence of actions that contain beaconing to an attacker-controlled webhook[.]web site, establishing persistence by means of Registry modifications, enabling macro execution, and turning off Outlook-related dialogue messages to evade detection.<\/p>\n<p>NotDoor is designed as an obfuscated Visible Primary for Functions (VBA) venture for Outlook that makes use of the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/office\/vba\/api\/outlook.application.mapilogoncomplete\" rel=\"noopener\" target=\"_blank\">Utility.MAPILogonComplete<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/office\/vba\/api\/outlook.application.newmailex\" rel=\"noopener\" target=\"_blank\">Utility.NewMailEx<\/a> occasions to run the payload each time Outlook is began or a brand new e mail arrives.<\/p>\n<p>It then proceeds to create a folder on the path %TEMPpercentTemp if it doesn&#8217;t exist, utilizing it as a staging folder to retailer TXT information created throughout the course of the operation and exfiltrate them to a Proton Mail handle. It additionally parses incoming messages for a set off string, resembling &#8220;Day by day Report,&#8221; inflicting it to extract the embedded instructions to be executed.<\/p>\n<p>The malware helps 4 totally different instructions &#8211;<\/p>\n<ul>\n<li>cmd, to execute instructions and return the usual output as an e mail attachment<\/li>\n<li>cmdno, to execute instructions<\/li>\n<li>dwn, to exfiltrate information from the sufferer&#8217;s pc by sending them as e mail attachments<\/li>\n<li>upl, to drop information to the sufferer&#8217;s pc<\/li>\n<\/ul>\n<p>&#8220;Information exfiltrated by the malware are saved within the folder,&#8221; LAB52 stated. &#8220;The file contents are encoded utilizing the malware&#8217;s customized encryption, despatched by way of e mail, after which deleted from the system.&#8221;<\/p>\n<p>The disclosure comes as Beijing-based 360 Menace Intelligence Heart detailed <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/08\/cert-ua-warns-of-hta-delivered-c.html\" rel=\"noopener\" target=\"_blank\">Gamaredon<\/a>&#8216;s (aka APT-C-53) evolving tradecraft, highlighting its use of Telegram-owned Telegraph as a dead-drop resolver to level to command-and-control (C2) infrastructure.<\/p>\n<p>The assaults are additionally notable for the abuse of Microsoft Dev Tunnels (devtunnels.ms), a service that enables builders to securely expose native net providers to the web for testing and debugging functions, as C2 domains for added stealth.<\/p>\n<p>&#8220;This system supplies twofold benefits: first, the unique C2 server IP is totally masked by Microsoft&#8217;s relay nodes, blocking risk intelligence tracebacks based mostly on IP repute,&#8221; the cybersecurity firm <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/mp.weixin.qq.com\/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247507351&amp;idx=1&amp;sn=0b8c9e5b3ff9d7b6551b3a69c151f7e0&amp;chksm=f9c1ee9eceb66788c94178eec69e10142c58dc7721874f9e4d3120d7ea952faa230221a6e2cc\" rel=\"noopener\" target=\"_blank\">stated<\/a>.<\/p>\n<div class=\"dog_two clear\"><center class=\"cf\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.uk\/cis-security-suite\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"CIS Build Kits\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjgkDdKZ4cf4syb2qVDyt76MS6-Iq2eLoi0woZ-R0yota4fauhbh-Ro40IHQaAcKWPGCf_BGWQSZd2VSdPJGkMefmls9YYuzVlgZ-mcdepOR1mlwFMTj2gqiGP5jHrt1VgmX72osdiB6x5DG-Tz1js5zJktU0pbKWFWqcqytxwSQZR9bRWMa9CBjiUDqomg\/s728-e100\/cis-d.png\" width=\"729\" height=\"91\"\/><\/a><\/center><\/div>\n<p>&#8220;Second, by exploiting the service&#8217;s capability to reset domains on a minute-by-minute foundation, the attackers can quickly rotate infrastructure nodes, leveraging the trusted credentials and visitors scale of mainstream cloud providers to take care of a virtually zero-exposure steady risk operation.&#8221;<\/p>\n<p>Assault chains entail using bogus <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2024\/12\/hackers-leveraging-cloudflare-tunnels.html\" rel=\"noopener\" target=\"_blank\">Cloudflare Employees domains<\/a> to distribute a Visible Primary Script like <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/harfanglab.io\/insidethelab\/gamaredons-pterolnk-analysis\/\" rel=\"noopener\" target=\"_blank\">PteroLNK<\/a>, which might propagate the an infection to different machines by copying itself to related USB drives, in addition to obtain further<\/p>\n<p>payloads.<\/p>\n<p>&#8220;This assault chain demonstrates a excessive stage of specialised design, using 4 layers of obfuscation (registry persistence, dynamic compilation, path masquerading, cloud service abuse) to hold out a totally covert operation from preliminary implantation to information exfiltration,&#8221; 360 Menace Intelligence Heart stated.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>\ue802Sep 04, 2025\ue804Ravie LakshmananCybersecurity \/ Malware The Russian state-sponsored hacking group tracked as APT28 has been attributed to a brand new Microsoft Outlook backdoor known as NotDoor in assaults concentrating on a number of firms from totally different sectors in NATO member international locations. NotDoor &#8220;is a VBA macro for Outlook designed to observe incoming [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":6335,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[5158,558,399,3347,1535,5160,5159,953,538],"class_list":["post-6333","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-apt28","tag-backdoor","tag-companies","tag-countries","tag-deploys","tag-nato","tag-notdoor","tag-outlook","tag-russian"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/6333","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6333"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/6333\/revisions"}],"predecessor-version":[{"id":6334,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/6333\/revisions\/6334"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/6335"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6333"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6333"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6333"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-13 15:25:56 UTC -->