HomeSecurityDetailed techniques for detecting the NotDoor Outlook Backdoor

Detailed techniques for detecting the NotDoor Outlook Backdoor

The Outlook backdoor malware, NotDoor, first appeared in threat campaigns detected by Lab52, the intelligence arm of Spanish company S2 Grupo.

See also: Trojanized ESET installers install Kalambur backdoor

NotDoor

Linked to APT28/Fancy Bear, NotDoor leverages malicious Outlook macros for persistent access and data theft. Attackers embed these macro payloads in Outlook data files to monitor incoming emails and execute hidden code on infected systems.

This has allowed advanced persistent threat groups to silently extract files, execute commands, and maintain covert control by abusing a trusted application.

The initial compromise often begins with DLL sideloading. Malicious actors place a maliciously crafted SSPICLI.dll alongside the legitimate OneDrive.exe, taking advantage of the way Windows prioritizes DLL loading.

The fake DLL allows the agent to execute commands and stage malware components without triggering alarms.

See also: FIN7: Using Windows SSH Backdoor for remote access

Detailed techniques for detecting the NotDoor Outlook Backdoor

The infection objects include several files: a real OneDrive.exe, SSPICLI.dll (malicious), tmp7E9C.dll (renamed to a legitimate DLL), and testtemp.ini containing the VBA macro. These details are critical for defenders who monitor suspicious file events and Registry modifications.

Security researchers at Splunk were among the first to thoroughly analyze NotDoor. Their in-depth study revealed coded PowerShell commands launched from OneDrive.exe and how the malware silently creates TEMP directories for dropped objects.

Splunk's detection guide helps defenders identify rogue processes that create PowerShell, network calls, and registry changes that enable automatic macro loading, disable security prompts, or enable all macros without warning.

See also: Hackers distribute SSH-Tor Backdoor via military documents

Detailed techniques for detecting the NotDoor Outlook Backdoor

This research provides valuable blueprints for creating reliable detection.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS