Alpha Cyber

Inside Fancy Bear’s Latest Attack Vector: Outlook-Based Backdoor with DNS & Email Exfiltration

In today’s threat landscape, attackers aren’t just breaking down doors they’re walking right through the front, disguised as trusted tools and workflows.

Alpha Cyber Research3 min readupdated 1 Apr 2026
APT-28 NotDoor Malware

Inside the Threat: Covert Outlook-Based Malware Leveraged by APT28 (Fancy Bear)

In today’s threat landscape, attackers aren’t just breaking down doors they’re walking right through the front, disguised as trusted tools and workflows. Nation-state actors like Fancy Bear (APT28) are setting new standards for stealth and sophistication, and one recent campaign we analyzed is a textbook example of how deeply a threat can embed itself in enterprise environments without raising a single red flag.

This particular operation demonstrates a calculated abuse of Microsoft Outlook and Visual Basic for Applications (VBA) to deploy a persistent, hard-to-detect backdoor. Unlike traditional malware that relies on noisy infrastructure or suspicious binaries, this threat is silent, persistent, and incredibly deceptive.

How the Attack Works

Once delivered via malicious Outlook macros, the malware installs itself and initiates a covert communication channel. From there, it quietly begins data exfiltration and system surveillance, without triggering alarms in most security environments.

Let’s break down the key features that make this campaign particularly dangerous:

What Makes This Attack Stand Out?

1. Data Exfiltration via Email

Rather than using noisy command-and-control servers or suspicious IPs, this backdoor exfiltrates victim data directly to an attacker-controlled email address:
a.matti444@proton[.]me

By using a legitimate email provider like ProtonMail, the attacker blends into everyday traffic. This method avoids many signature-based detection tools and circumvents monitoring systems that look for unusual outbound network traffic or external API calls.

2. Execution Verification Through Public Services

Once deployed, the malware checks in using both DNS and HTTP callbacks to a public endpoint:
webhook.site

This dual-channel validation confirms successful installation while eliminating the need for attacker-owned infrastructure. It also complicates attribution and blocks traditional C2 detection methods, since these callbacks mimic benign DNS lookups or HTTP requests to public, non-malicious services.

3. Abuse of Trusted Tools

The real genius of this attack lies in its use of legitimate Microsoft technology. Outlook and VBA macros are part of many business-critical processes. Most organizations allow them internally without restrictions.

By hiding in plain sight, within tools already trusted by your employees. The attacker avoids scrutiny. This makes detection extremely difficult, particularly for organizations without advanced behavioral monitoring, email sandboxing, or macro execution logging in place.

Why It Matters

This infrastructure mapping reflects a larger shift in attacker strategy: from loud, high-volume attacks to quiet, targeted operations designed for long-term persistence and data theft. Actors like APT28 aren’t relying on brute force anymore, they’re investing in stealth, legitimacy, and efficiency.

And it’s working.

Security teams relying solely on firewalls, antivirus, or even traditional EDR solutions may not catch these subtle signals until it’s too late. This kind of campaign is built to fly under the radar, especially in environments with limited visibility into email behavior, macro execution, or external DNS traffic.

What Can You Do?

Organizations must evolve to meet these threats head-on. That means:

  • Hardening email security policies, including disabling or restricting macros where possible.
  • Monitoring DNS and HTTP traffic for unusual patterns, even if they connect to benign domains.
  • Deploying behavioral detection and threat hunting to spot low-and-slow attacks before they escalate.
  • Conducting regular compromise assessments to uncover hidden backdoors or silent persistence mechanisms.

IOCs Hash Table:

TypeIndicatorTitle
FileHash-MD515e9255a3e3401e5f6578d2ac45b7850SUSP_PS1_JAB_Pattern_Jun22_1
FileHash-MD5f8d9b7c864fb7558e8bad4cfb5c8e6ff
FileHash-SHA13b80a13199564e3d8a9d26e14defabee136638f8SUSP_PS1_JAB_Pattern_Jun22_1
FileHash-SHA1a45ab1a9dec488278ee9682735d42d61dfc38b9e
FileHash-SHA2565a88a15a1d764e635462f78a0cd958b17e6d22c716740febc114a408eef66705SUSP_PS1_JAB_Pattern_Jun22_1
FileHash-SHA2568f4bca3c62268fff0458322d111a511e0bcfba255d5ab78c45973bd293379901
FileHash-SHA256fcb6dc17f96af2568d7fa97a6087e4539285141206185aec5c85fa9cf73c9193

How We Help

At Alpha Cyber, we specialize in identifying and dismantling advanced, covert threats like this one. From email security audits to proactive threat hunting, we offer the expertise and technology to uncover what others miss.

If your business depends on Microsoft 365, Outlook, or VBA-driven workflows, now is the time to evaluate your exposure. Don’t wait until after a breach to find out how stealthy today’s attackers have become.

Stay ahead of the threats you can’t see. Contact us today to schedule a security assessment.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]