NotDoor, also known as GONEPOSTAL, is a Microsoft Outlook backdoor for Windows associated with the Russian military intelligence-linked threat actor APT28, also known as Fancy Bear, Pawn Storm, and UAC-0001. Implemented as Outlook VBA macros, it supports persistent espionage against organizations across multiple sectors in NATO member states. Campaigns deploying it have targeted Ukrainian and European government, military, diplomatic, maritime, transportation, and logistics organizations.
NotDoor integrates with Outlook event handling and monitors incoming messages for a predefined trigger word. Its functionality includes command execution, uploading files to compromised systems, and exfiltrating data. Email-collection variants monitor mailbox folders and automatically forward messages and attachments to attacker-controlled email accounts. They track processed messages to avoid duplicate forwarding and remove outgoing copies to conceal the activity. Installation weakens Outlook macro security, suppresses security warnings, and enables automatic macro loading to sustain execution through Outlook.
In January 2026 campaigns, NotDoor was deployed through multi-stage infection chains initiated by spear-phishing attachments exploiting Microsoft Office security feature bypass vulnerability CVE-2026-21509. Opening a malicious document caused embedded OLE objects to retrieve external payloads through WebDAV without requiring document macros to be enabled. NotDoor served as an Outlook-focused payload for long-term email intelligence collection, alongside separate infection branches deploying other implants. MiniDoor is a stripped-down derivative focused on email theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Patching CVE-2026–21509 is necessary, but not sufficient. Malicious .doc → CVE- 2026 - 21509 exploit → LNK shortcut + SimpleLoader DLL → EhStoreShell .dll (steganography loader) → SplashScreen .png (shellcode hidden in PNG image) → CovenantGrunt (in-memory .NET backdoor) → filen .io (C2 communication)
CVE-2026-21513 zero-day: Exploited at least 11 days before the February 10, 2026 patch release... By combining zero-day exploitation (CVE-2026-21513) with rapid weaponization of newly disclosed vulnerabilities (CVE-2026-21509)... Immediate mitigations Patching: Prioritize the remediation of both CVE-2026-21509 and CVE-2026-21513 across the entire fleet immediately.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers from Trend Micro assess that this advanced toolkit represents a strategic expansion of the group's older "NotDoor" malware network.
The exploitation delivers a multi-stage infection chain culminating in the NotDoor Outlook backdoor and Covenant Grunt implants.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
upon detection, allows attackers to exfiltrate data, upload files, and execute commands on the compromised system
The campaign relies on a layered infection chain and new tooling, starting with a lightweight loader and progressing to an Outlook VBA backdoor called NotDoor... The loader either... drops VbaProject.OTM for NotDoor payload.
CVE-2026-21509, a remote code execution vulnerability in Microsoft Office affecting RTF and OLE document processing... weaponized the flaw in malicious RTF files targeting Ukrainian government agencies and European defense, transportation, and diplomatic entities.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware ecosystem/backdoor lineage that PRISMEX is assessed to expand upon in Pawn Storm campaigns.
An Outlook backdoor implemented via VbaProject.OTM that abuses Outlook macro/event functionality, including Application_MAPILogonComplete and Application_NewMailEx, effectively turning Outlook into a mail-monitoring backdoor.
An Outlook backdoor used as the final payload in a multi-stage spear-phishing exploitation chain tied to CVE-2026-21509 campaigns.
An Outlook VBA backdoor for persistent email surveillance and exfiltration. It disables Outlook macro security, installs VbaProject.OTM, triggers on Outlook login and new mail, and forwards collected messages to attacker-controlled email accounts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.