NotDoor is an Outlook-focused backdoor implemented as a malicious VBA macro for Microsoft Outlook and attributed in the provided reporting to APT28 (Fancy Bear/UAC-0001), a Russia-linked GRU-associated threat actor. It has been described as used in espionage campaigns targeting government, military, diplomatic, maritime, transport, and other organizations in Ukraine and across NATO-aligned or Eastern European countries. The malware is also referred to in the content as GONEPOSTAL, and some reporting notes MiniDoor as a stripped-down variant of NotDoor.
The malware is designed for long-term email intelligence collection rather than interactive command-and-control. Reported behavior includes monitoring Outlook mailboxes and incoming messages, using Outlook event handlers such as Application_MAPILogonComplete and Application_NewMailEx for execution, automatically forwarding sensitive emails and attachments, saving messages as .msg files, deleting trigger or processed emails, and purging evidence by setting DeleteAfterSubmit to True. Multiple sources in the content state that it monitored folders including Inbox, Drafts, and Junk, and forwarded collected mail to attacker-controlled addresses including chmilewskii@outlook.com, chmilewskii@proton.me, ahmeclaw2002@outlook.com, ahmeclaw@proton.me, and a.matti444@proton.me. Some reporting also states that NotDoor can exfiltrate data, upload files, and execute commands when triggered by predefined words or phrases in incoming email, including an analyzed trigger string of "Daily Report," and that it supports commands such as cmd, cmdno, dwn, and upl.
Installation and persistence behavior described in the content centers on Outlook macro abuse. NotDoor writes or installs a malicious VbaProject.OTM file in %APPDATA%\Microsoft\Outlook; one reported sample has SHA-256 7ccf7e8050c66eed69f35159042d8043032f8afe48ae1f51fce75ce2c51395f2. The malware or its loader modifies Outlook-related registry settings to weaken protections and ensure macro loading, including HKCU\Software\Microsoft\Office\16.0\Outlook\Security\Level set to 1 and HKCU\Software\Microsoft\Office\16.0\Outlook\LoadMacroProviderOnBoot set to 1. Additional reporting states it suppresses Outlook warning dialogs via Outlook options registry changes. One documented deployment chain used DLL side-loading through legitimate Microsoft OneDrive.exe to load a malicious SSPICLI.dll, which then ran Base64-encoded PowerShell to copy a payload from c:\programdata\testtemp.ini into VbaProject.OTM and verify execution via webhook.site DNS and HTTP callbacks. Reported hashes from that chain include SSPICLI.dll SHA-256 5a88a15a1d764e635462f78a0cd958b17e6d22c716740febc114a408eef66705 and testtemp.ini SHA-256 8f4bca3c62268fff0458322d111a511e0bcfba255d5ab78c45973bd293379901.
In the 2026 reporting, NotDoor appears as one branch of a broader APT28 exploitation chain leveraging CVE-2026-21509 in malicious Office documents. That chain is described as using spear-phishing with weaponized RTF/DOC files, embedded OLE objects, and WebDAV retrieval of follow-on payloads, culminating either in NotDoor or in other implants such as Covenant Grunt, BeardShell, or related loaders. The content also notes associated artifacts and behaviors around this campaign, including Outlook macro creation, registry modification, and suspicious file writes, which were used by Splunk detections and datasets focused on NotDoor malware execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Patching CVE-2026–21509 is necessary, but not sufficient. Malicious .doc → CVE- 2026 - 21509 exploit → LNK shortcut + SimpleLoader DLL → EhStoreShell .dll (steganography loader) → SplashScreen .png (shellcode hidden in PNG image) → CovenantGrunt (in-memory .NET backdoor) → filen .io (C2 communication)
CVE-2026-21513 zero-day: Exploited at least 11 days before the February 10, 2026 patch release... By combining zero-day exploitation (CVE-2026-21513) with rapid weaponization of newly disclosed vulnerabilities (CVE-2026-21509)... Immediate mitigations Patching: Prioritize the remediation of both CVE-2026-21509 and CVE-2026-21513 across the entire fleet immediately.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
VbaProject.OTM (NotDoor Outlook backdoor) SHA-256: 7ccf7e8050c66eed69f35159042d8043032f8afe48ae1f51fce75ce2c51395f2
The exploitation delivers a multi-stage infection chain culminating in the NotDoor Outlook backdoor and Covenant Grunt implants.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
upon detection, allows attackers to exfiltrate data, upload files, and execute commands on the compromised system
The campaign relies on a layered infection chain and new tooling, starting with a lightweight loader and progressing to an Outlook VBA backdoor called NotDoor... The loader either... drops VbaProject.OTM for NotDoor payload.
CVE-2026-21509, a remote code execution vulnerability in Microsoft Office affecting RTF and OLE document processing... weaponized the flaw in malicious RTF files targeting Ukrainian government agencies and European defense, transportation, and diplomatic entities.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Outlook backdoor implemented via VbaProject.OTM that abuses Outlook macro/event functionality, including Application_MAPILogonComplete and Application_NewMailEx, effectively turning Outlook into a mail-monitoring backdoor.
An Outlook backdoor used as the final payload in a multi-stage spear-phishing exploitation chain tied to CVE-2026-21509 campaigns.
An Outlook VBA backdoor for persistent email surveillance and exfiltration. It disables Outlook macro security, installs VbaProject.OTM, triggers on Outlook login and new mail, and forwards collected messages to attacker-controlled email accounts.
Referenced as a prior malware ecosystem or lineage linked to the current campaign, associated with long-term espionage and related technically to PRISMEX activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.