NotDoor is an Outlook-focused backdoor attributed to APT28, the Russia-linked espionage group also tracked as Fancy Bear, UAC-0001, Forest Blizzard, and Pawn Storm. It is implemented as a malicious VBA project for Microsoft Outlook on Windows and is designed primarily for long-term email intelligence collection rather than interactive remote administration.
The malware operates by embedding itself into Outlook’s macro environment and using Outlook event handlers to execute at client startup and when new mail arrives. Reported variants monitor mailbox content for predefined trigger phrases and can automatically process messages from folders such as Inbox, Drafts, and Junk. Documented behavior includes forwarding selected emails and attachments to attacker-controlled mailboxes, saving messages for exfiltration, deleting trigger messages, suppressing evidence by purging sent items, and marking already processed messages to avoid duplication. Some reporting also describes command execution and file upload or download functionality triggered through specially crafted emails, indicating that certain variants extend beyond passive collection into broader host-level tasking.
NotDoor is associated with campaigns against government, military, diplomatic, transport, maritime, and other organizations in Ukraine and multiple NATO or NATO-aligned European countries. It has been linked to spearphishing operations that rapidly weaponized Microsoft Office vulnerabilities including CVE-2026-21509, where malicious Office documents initiated multi-stage infection chains that culminated in either NotDoor or other APT28 implants such as Covenant Grunt and BeardShell. Separate reporting also describes deployment through DLL sideloading involving Microsoft OneDrive components to install the Outlook VBA payload and weaken Outlook security settings.
To establish execution and persistence, NotDoor-related activity has been observed modifying Outlook settings to lower macro protections, force macro loading at boot, and suppress warning dialogs. The malware’s tradecraft emphasizes stealth and durability inside a user’s normal email workflow, turning the Outlook client into a covert collection mechanism while minimizing overt command-and-control traffic. MiniDoor has been described as a simplified variant derived from NotDoor and focused more narrowly on email theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Patching CVE-2026–21509 is necessary, but not sufficient. Malicious .doc → CVE- 2026 - 21509 exploit → LNK shortcut + SimpleLoader DLL → EhStoreShell .dll (steganography loader) → SplashScreen .png (shellcode hidden in PNG image) → CovenantGrunt (in-memory .NET backdoor) → filen .io (C2 communication)
CVE-2026-21513 zero-day: Exploited at least 11 days before the February 10, 2026 patch release... By combining zero-day exploitation (CVE-2026-21513) with rapid weaponization of newly disclosed vulnerabilities (CVE-2026-21509)... Immediate mitigations Patching: Prioritize the remediation of both CVE-2026-21509 and CVE-2026-21513 across the entire fleet immediately.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TrendAI Research assesses that the campaigns that use PrismexStager likely represent a strategic expansion of the "NotDoor" ecosystem, extending its multiple infection chains to now include rapid exploitation of newly disclosed vulnerabilities.
The exploitation delivers a multi-stage infection chain culminating in the NotDoor Outlook backdoor and Covenant Grunt implants.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
upon detection, allows attackers to exfiltrate data, upload files, and execute commands on the compromised system
The campaign relies on a layered infection chain and new tooling, starting with a lightweight loader and progressing to an Outlook VBA backdoor called NotDoor... The loader either... drops VbaProject.OTM for NotDoor payload.
CVE-2026-21509, a remote code execution vulnerability in Microsoft Office affecting RTF and OLE document processing... weaponized the flaw in malicious RTF files targeting Ukrainian government agencies and European defense, transportation, and diplomatic entities.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware ecosystem/backdoor lineage that PRISMEX is assessed to expand upon in Pawn Storm campaigns.
An Outlook backdoor implemented via VbaProject.OTM that abuses Outlook macro/event functionality, including Application_MAPILogonComplete and Application_NewMailEx, effectively turning Outlook into a mail-monitoring backdoor.
An Outlook backdoor used as the final payload in a multi-stage spear-phishing exploitation chain tied to CVE-2026-21509 campaigns.
An Outlook VBA backdoor for persistent email surveillance and exfiltration. It disables Outlook macro security, installs VbaProject.OTM, triggers on Outlook login and new mail, and forwards collected messages to attacker-controlled email accounts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.