logo

New Dohdoor Malware Attacking Schools and Health Care Sectors in U.S. via Multi-Stage Attack Chain

ID: f99abda9-b51a-50fd-8e93-c8c89cc1edc2

STIX ID: report--f99abda9-b51a-50fd-8e93-c8c89cc1edc2

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-02-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Executive summary:** A sophisticated multi-stage malware campaign named "Dohdoor" (attributed to actor UAT-10027) has been targeting U.S. education and healthcare organizations since at least December 2025; it uses phishing-delivered PowerShell, DLL sideloading via living-off-the-land binaries, DoH-based C2 over Cloudflare, position-dependent payload decryption, process hollowing, and ntdll syscall unhooking to maintain persistence and evade EDR, and the report provides IoCs and detection signatures for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.