The Outlook backdoor malware, NotDoor, first appeared in threat campaigns detected by Lab52, the intelligence arm of Spanish company S2 Grupo.
See also: Trojanized ESET installers install Kalambur backdoor

Linked to APT28/Fancy Bear, NotDoor leverages malicious Outlook macros for persistent access and data theft. Attackers embed these macro payloads in Outlook data files to monitor incoming emails and execute hidden code on infected systems.
This has allowed advanced persistent threat groups to silently extract files, execute commands, and maintain covert control by abusing a trusted application.
The initial compromise often begins with DLL sideloading. Malicious actors place a maliciously crafted SSPICLI.dll alongside the legitimate OneDrive.exe, taking advantage of the way Windows prioritizes DLL loading.
The fake DLL allows the agent to execute commands and stage malware components without triggering alarms.
See also: FIN7: Using Windows SSH Backdoor for remote access

The infection objects include several files: a real OneDrive.exe, SSPICLI.dll (malicious), tmp7E9C.dll (renamed to a legitimate DLL), and testtemp.ini containing the VBA macro. These details are critical for defenders who monitor suspicious file events and Registry modifications.
Security researchers at Splunk were among the first to thoroughly analyze NotDoor. Their in-depth study revealed coded PowerShell commands launched from OneDrive.exe and how the malware silently creates TEMP directories for dropped objects.
Splunk's detection guide helps defenders identify rogue processes that create PowerShell, network calls, and registry changes that enable automatic macro loading, disable security prompts, or enable all macros without warning.
See also: Hackers distribute SSH-Tor Backdoor via military documents

This research provides valuable blueprints for creating reliable detection.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
