Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2026-02-04 ⋅ StrikeReady ⋅ APT28’s Stealthy Multi-Stage Campaign Leveraging CVE‑2026‑21509 and Cloud C2 Infrastructure ... 2026-02-02 ⋅ Zscaler ⋅ APT28 Leverages CVE-2026-21509 in Operation Neusploit | 2025-09-05 ⋅ Kroll ⋅ FANCY BEAR GONEPOSTAL – Espionage Tool Provides Backdoor Access to Microsoft Outlook
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2025-09-05 ⋅ Kroll ⋅ FANCY BEAR GONEPOSTAL – Espionage Tool Provides Backdoor Access to Microsoft Outlook
VbaProject.OTM contains VBA macros which are executed by Microsoft Outlook, constituting a backdoor which Kroll analysts have titled GONEPOSTAL.
VbaProject.OTM contains VBA macros which are executed by Microsoft Outlook, constituting a backdoor which Kroll analysts have titled GONEPOSTAL.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
cmd -> ExecuteShellCommand() -> captures output -> WriteByteChunksToFiles() cmdNo -> TryExecuteCommand() (no output)
The DLLMain function starts by defining several C++ strings that contain the parameters to execute an encoded PowerShell command... creating a full PowerShell command line which then passes to the “CreateProcessW” Windows API function executing the command.
VbaProject.OTM contains VBA macros which are executed by Microsoft Outlook, constituting a backdoor which Kroll analysts have titled GONEPOSTAL.
The SSPICLI.dll is an unsigned malicious DLL pretending to be Microsoft’s legitimate signed DLL of the same name... The malicious DLL uses its export table to forward all 105 exported library functions of the legitimate DLL to the renamed DLL supplied alongside, allowing any application using the malicious DLL to appear to work normally.
Cleanup DeleteMailAndMatchInDeleted() removes processed emails from the inbox and deleted items... Firstly, files for egress are read and converted to base64, with the original file deleted.
Of note here is the dwCreationFlags value of 0x8000000, which stops the creation of an application window.
The SSPICLI.dll is an unsigned malicious DLL pretending to be Microsoft’s legitimate signed DLL of the same name... The malicious DLL uses its export table to forward all 105 exported library functions of the legitimate DLL to the renamed DLL supplied alongside, allowing any application using the malicious DLL to appear to work normally.
This results in a backdoor utilizing the email service itself as a C2 channel... ExecutePayload() creates and sends an Outlook email to the attacker.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage tool that provides backdoor access to Microsoft Outlook; associated with APT28/Fancy Bear.
An Outlook VBA macro backdoor loaded via VbaProject.OTM and registry changes that enable Outlook macro providers on startup. It uses Outlook email itself as the C2 channel, monitors incoming mail for command signatures, executes shell commands, supports file upload/download via chunked email attachments, exfiltrates results by sending attacker-controlled emails, and deletes processed messages for stealth.
Espionage tool that provides backdoor access to Microsoft Outlook.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.