MiniDoor is a lightweight Microsoft Outlook email-stealing implant associated with APT28, also known as Fancy Bear, Pawn Storm, Sednit, Sofacy, UAC-0001, BlueDelta, and Forest Blizzard. It has been assessed as a stripped-down variant of NotDoor that removes broader backdoor functionality in favor of focused mailbox collection and forwarding. The malware has been observed in Operation Neusploit and related campaigns targeting government, military, and other public-sector or strategically relevant organizations in Ukraine, Slovakia, Romania, and other parts of Central and Eastern Europe.
MiniDoor is deployed through malicious Office document exploitation, including weaponized RTF files used with CVE-2026-21509, typically delivered via spearphishing lures localized to the victim’s language and region. In the observed chain, an initial dropper DLL decrypts and installs a malicious Outlook VBA project, weakens Outlook security settings to permit macro execution and suppress warnings, and configures the project to load automatically when Outlook starts.
Once active, MiniDoor monitors Outlook events such as mailbox logon and new-mail activity, enumerates selected mailbox folders, and harvests messages from the victim’s account. It forwards stolen emails to attacker-controlled mailboxes while marking already processed items to avoid duplicate forwarding and suppressing normal user-visible artifacts such as retained sent copies. Its core purpose is email exfiltration for espionage collection rather than interactive remote administration.
MiniDoor targets Windows systems with Microsoft Outlook installed and is notable for abusing Outlook VBA as its execution environment. Its use alongside other APT28 tooling, including PixyNetLoader and Covenant Grunt, places it within a broader intrusion ecosystem emphasizing stealthy collection, selective targeting, and rapid operationalization of newly disclosed Microsoft Office vulnerabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Spoločnosť Microsoft vydala mimoriadne bezpečnostné aktualizácie kancelárskeho balíka Microsoft Office, ktoré opravujú aktívne zneužívanú zero-day zraniteľnosť. CVE-2026-21509 možno zneužiť podvrhnutím špeciálne vytvorených súborov na obídenie bezpečnostných mechanizmov pre ochranu pred zneužitím niektorých funkcií COM/OLE a získanie úplnej kontroly nad systémom. | Cieľom je nainštalovať malvér MiniDoor (kradne e-maily) a PixyNetLoader, ktorý nainštaluje útočný nástroj Covenant.
CVE-2026-21513 zero-day: Exploited at least 11 days before the February 10, 2026 patch release... By combining zero-day exploitation (CVE-2026-21513) with rapid weaponization of newly disclosed vulnerabilities (CVE-2026-21509)... Immediate mitigations Patching: Prioritize the remediation of both CVE-2026-21509 and CVE-2026-21513 across the entire fleet immediately.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Path A (PRISMEX) or Path B (MiniDoor Chain, which is reported by Zscaler ThreatLabz). According to Zscaler ThreatLabz, the MiniDoor backdoor deployed in this campaign is a variant of NotDoor.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The first dropper variant DLL is responsible for deploying a malicious Microsoft Outlook Visual Basic for Applications (VBA) project named MiniDoor.
Sets the relevant Windows registry keys to downgrade Outlook security and allow the malicious project to load automatically each time Microsoft Outlook launches.
“Strings decrypted using a hardcoded 1-byte XOR key… rolling XOR key…” and “Strings in this sample are XOR-encoded… and then Base64-encoded.”
"Deleting these messages from the ‘Sent’ folder so the victim never knows they were targeted."
The threat actor employed server-side evasion techniques, responding with the malicious DLL only when requests originated from the targeted geographic region and included the correct User-Agent HTTP header.
MiniDoor is a C++-based DLL file that steals a user's emails in various folders (Inbox, Junk, and Drafts) and forwards them to two hard-coded threat actor email addresses
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor used as an alternate payload chain in the same campaign and described as a variant of NotDoor.
An implant/backdoor payload deployed via weaponized RTF lures in the referenced Operation Neusploit activity targeting Central and Eastern Europe.
Backdoor/email-stealing tool deployed via a dropper DLL; modifies registry keys to weaken Microsoft Outlook security and enables theft/exfiltration of emails, supporting long-term espionage access.
Lightweight 64-bit DLL that drops an encrypted Outlook VBA project, weakens Outlook macro security via registry changes, and automates email collection and exfiltration by forwarding messages to actor-controlled addresses while avoiding Sent-folder artifacts and duplicate forwarding.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.