Inside Fancy Bear’s Latest Attack Vector: Outlook-Based Backdoor with DNS & Email Exfiltration
In today’s threat landscape, attackers aren’t just breaking down doors they’re walking right through the front, disguised as trusted tools and workflows.

Inside the Threat: Covert Outlook-Based Malware Leveraged by APT28 (Fancy Bear)
In today’s threat landscape, attackers aren’t just breaking down doors they’re walking right through the front, disguised as trusted tools and workflows. Nation-state actors like Fancy Bear (APT28) are setting new standards for stealth and sophistication, and one recent campaign we analyzed is a textbook example of how deeply a threat can embed itself in enterprise environments without raising a single red flag.
This particular operation demonstrates a calculated abuse of Microsoft Outlook and Visual Basic for Applications (VBA) to deploy a persistent, hard-to-detect backdoor. Unlike traditional malware that relies on noisy infrastructure or suspicious binaries, this threat is silent, persistent, and incredibly deceptive.
How the Attack Works

Once delivered via malicious Outlook macros, the malware installs itself and initiates a covert communication channel. From there, it quietly begins data exfiltration and system surveillance, without triggering alarms in most security environments.
Let’s break down the key features that make this campaign particularly dangerous:
What Makes This Attack Stand Out?
1. Data Exfiltration via Email
Rather than using noisy command-and-control servers or suspicious IPs, this backdoor exfiltrates victim data directly to an attacker-controlled email address:
a.matti444@proton[.]me
By using a legitimate email provider like ProtonMail, the attacker blends into everyday traffic. This method avoids many signature-based detection tools and circumvents monitoring systems that look for unusual outbound network traffic or external API calls.
2. Execution Verification Through Public Services
Once deployed, the malware checks in using both DNS and HTTP callbacks to a public endpoint:
webhook.site
This dual-channel validation confirms successful installation while eliminating the need for attacker-owned infrastructure. It also complicates attribution and blocks traditional C2 detection methods, since these callbacks mimic benign DNS lookups or HTTP requests to public, non-malicious services.
3. Abuse of Trusted Tools
The real genius of this attack lies in its use of legitimate Microsoft technology. Outlook and VBA macros are part of many business-critical processes. Most organizations allow them internally without restrictions.
By hiding in plain sight, within tools already trusted by your employees. The attacker avoids scrutiny. This makes detection extremely difficult, particularly for organizations without advanced behavioral monitoring, email sandboxing, or macro execution logging in place.
Why It Matters
This infrastructure mapping reflects a larger shift in attacker strategy: from loud, high-volume attacks to quiet, targeted operations designed for long-term persistence and data theft. Actors like APT28 aren’t relying on brute force anymore, they’re investing in stealth, legitimacy, and efficiency.
And it’s working.
Security teams relying solely on firewalls, antivirus, or even traditional EDR solutions may not catch these subtle signals until it’s too late. This kind of campaign is built to fly under the radar, especially in environments with limited visibility into email behavior, macro execution, or external DNS traffic.
What Can You Do?
Organizations must evolve to meet these threats head-on. That means:
- Hardening email security policies, including disabling or restricting macros where possible.
- Monitoring DNS and HTTP traffic for unusual patterns, even if they connect to benign domains.
- Deploying behavioral detection and threat hunting to spot low-and-slow attacks before they escalate.
- Conducting regular compromise assessments to uncover hidden backdoors or silent persistence mechanisms.
IOCs Hash Table:
| Type | Indicator | Title |
|---|---|---|
| FileHash-MD5 | 15e9255a3e3401e5f6578d2ac45b7850 | SUSP_PS1_JAB_Pattern_Jun22_1 |
| FileHash-MD5 | f8d9b7c864fb7558e8bad4cfb5c8e6ff | |
| FileHash-SHA1 | 3b80a13199564e3d8a9d26e14defabee136638f8 | SUSP_PS1_JAB_Pattern_Jun22_1 |
| FileHash-SHA1 | a45ab1a9dec488278ee9682735d42d61dfc38b9e | |
| FileHash-SHA256 | 5a88a15a1d764e635462f78a0cd958b17e6d22c716740febc114a408eef66705 | SUSP_PS1_JAB_Pattern_Jun22_1 |
| FileHash-SHA256 | 8f4bca3c62268fff0458322d111a511e0bcfba255d5ab78c45973bd293379901 | |
| FileHash-SHA256 | fcb6dc17f96af2568d7fa97a6087e4539285141206185aec5c85fa9cf73c9193 |
How We Help
At Alpha Cyber, we specialize in identifying and dismantling advanced, covert threats like this one. From email security audits to proactive threat hunting, we offer the expertise and technology to uncover what others miss.
If your business depends on Microsoft 365, Outlook, or VBA-driven workflows, now is the time to evaluate your exposure. Don’t wait until after a breach to find out how stealthy today’s attackers have become.
Stay ahead of the threats you can’t see. Contact us today to schedule a security assessment.



