GONEPOSTAL
Aliases: Cordyceps, NOTDOOR
- Malware type
- backdoor, dropper
- Last IoC activity
- 2026-05-21 06:48:25
- Profile updated
- 2026-07-07 15:03:42
Context
The malware consists of a dropper DLL and an obfuscated, password protected VbaProject.OTM file, which houses macros written for Microsoft Outlook. The malware was originally written by Greg Linares as a backdoor POC called Cordyceps, and presented at Hushcon in 2017.
Exploited vulnerabilities
- CVE-2026-21509 (vulnerability)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Gonepostal (report)
- strikeready.com — Apt28S Campaign Leveraging Cve%E2%80%912026%E2%80%9121509 And Cloud C2 Infrastructure (report)
- trellix.com — Apt28 Stealthy Campaign Leveraging Cve 2026 21509 Cloud C2 (report)
- x.com — 1963608292468346968 (report)
- kroll.com — Fancy Bear Gonepostal Espionage Tool Backdoor Access Microsoft Outlook (report)
- lab52.io — Analyzing Notdoor Inside Apt28S Expanding Arsenal (report)
- prezi.com — Ez3Csnmxpmofiwehwtje (report)