logo

Suspected Nork digital intruders caught breaking into US healthcare, education orgs

ID: c76d6017-9b83-5416-9838-9b63b0122b32

STIX ID: report--c76d6017-9b83-5416-9838-9b63b0122b32

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-02-27

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Cisco Talos identified an ongoing campaign (since at least December) delivering a new loader/backdoor named Dohdoor that sideloads malicious DLLs (e.g., propsys.dll), downloads and executes additional payloads (including Cobalt Strike), and employs evasive techniques such as process hollowing, ntdll unhooking to bypass EDR, and DNS-over-HTTPS via Cloudflare for C2 resolution; observed victims include educational institutions and an elderly-care healthcare facility. Talos tracks the cluster as UAT-10027 and notes technical overlaps with Lazarus Group tooling but assigns low confidence to North Korean attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.