Tag: Outlook Backdoor

Russian APT28 Deploys “NotDoor” Outlook Backdoor Against Companies in NATO Countries
News

Russian APT28 Deploys “NotDoor” Outlook Backdoor Against Companies in NATO Countries

A new Microsoft Outlook backdoor known as NotDoor has been linked to attacks by the Russian state-sponsored hacker collective known as APT28 that target several businesses across various industries in NATO member nations. NotDoor is an Outlook VBA macro that scans incoming emails for a particular trigger word, according to S2 Grupo's LAB52 threat intelligence team. An attacker can upload files, run commands on the victim's computer, and exfiltrate data when such an email is discovered. The Spanish cybersecurity firm said that the word "Nothing" is used in the source code, which is how the artifact got its name. The activity demonstrates how Outlook is abused as a covert communication, data exfiltration, and malware distribution tool. Analysis reveals that the virus is distributed...