A sophisticated backdoor, dubbed NotDoor, allows attackers to extract data, upload files, and execute commands on compromised computers. The new backdoor targets Microsoft Outlook and is linked to the notorious Russian cyberespionage APT28.

Malicious actors use it to steal data and take control of the victim's computer. The findings were published by LAB52, the threat intelligence unit of Spanish cybersecurity firm S2 Grupo.
NotDoor backdoor
NotDoor is a silent malware written in Visual Basic for Applications (VBA), the scripting language used to automate tasks within Microsoft Office applications. The backdoor is designed to monitor a victim's incoming emails for specific keywords, such as 'Daily Report'. When an email containing the trigger is detected, the malware is activated, allowing attackers to execute malicious commands. The name 'NotDoor' was given by researchers due to the use of the word 'Nothing' in the malware's code.
See also: Phishing campaign targeted Google Cloud and Cloudflare for 3 years
The malware cleverly exploits features Outlook to remain hidden and maintain its persistent presence. It uses event-driven VBA triggers, such as Application_MAPILogonComplete, which runs when Outlook starts, and Application_NewMailEx, which fires when a new email arrives.

Detection avoidance techniques
To avoid detection by security software, NotDoor uses several sophisticated techniques:
- Code Obfuscation: The malware code is intentionally scrambled with random variable names and a custom encoding method to make analysis difficult.
- DLL Side-Loading: It uses a legitimate, signed Microsoft file, OneDrive.exe, to load a malicious DLL file. This technique helps the malware appear as a trusted process.
- Registry Modification: To remain persistent, NotDoor modifies Outlook's registry settings. It disables security warnings and suppresses other prompts, allowing it to operate silently without notifying the user.
Once activated, the backdoor creates a hidden directory to store temporary files, which are then exported to an email address controlled by the attacker. The malware confirms its successful execution by sending callbacks to a webhook site.
See also: RapperBot: Takes over devices and carries out DDoS attacks
Russian hackers APT28
The APT28 group is a known threat actor linked to the Main Intelligence Directorate of the Russian General Staff (GRU). Active for over a decade, the group is behind numerous high-profile attacks, including the breach of the Democratic National Committee (DNC) in 2016 during the US presidential election.
This new tool (NotDoor backdoor) demonstrates the team's continuous evolution and its ability to develop new methods to bypass modern defense mechanisms.
According to S2 Grupo, the NotDoor malware has already been used to compromise many companies, in various sectors, in NATO member countries.
NotDoor highlights a worrying pattern: cyberattacks are becoming more and more “natural” in the flow of everyday tools that organizations use. Exploiting Outlook and VBA triggers is not just a technical feat, but a strategic choice, since users hardly suspect that an office application can function as a Trojan horse.
The most worrying element is not only the technological complexity, but the fact that attacks of this type primarily target the “routine.” When malware is activated through a seemingly innocent email, the lines of defense are exhausted by human inaction.
See also: Iran's Homeland Justice Targets Over 100 Embassy Emails
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Furthermore, the connection to APT28 underscores the state-based nature of the threat: this is not a random cybercriminal group, but an actor aiming for geopolitical gains. This makes NotDoor not just a new malicious tool, but an indicator of the direction modern cyberwarfare is taking.
Protection
Security experts recommend that organizations disable macros by default on their systems, closely monitor any unusual activity within Outlook, and inspect email-based triggers that could exploit such malware.
