logo

New Dohdoor malware campaign targets education and health care

ID: 3fc8b98e-cbd9-5def-9f95-73219b219181

STIX ID: report--3fc8b98e-cbd9-5def-9f95-73219b219181

Feed Name: Cisco Talos

Threat Score
82/100

Date Published: 2026-02-26

Date Updated: 2026-04-27

Author: Alex Karkins

...
...

Cisco Talos reports an active multi-stage intrusion campaign (since at least Dec 2025) by actor UAT-10027 delivering a backdoor named Dohdoor that uses DNS-over-HTTPS to Cloudflare for stealthy C2, DLL sideloading and reflective payload execution (process hollowing), custom position-dependent XOR-SUB decryption, and an EDR unhooking syscall bypass. The actor targeted U.S. education and healthcare, abused living-off-the-land binaries, used deceptive subdomains/TLDs to evade detection, and left IOCs and signatures (ClamAV, Snort) with low-confidence overlap to North Korean APT tradecraft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.