logo

UAT-10027 campaign hits U.S. education and healthcare with stealthy Dohdoor backdoor

ID: 820b049e-e67b-575c-8cfb-3b75cb091599

STIX ID: report--820b049e-e67b-575c-8cfb-3b75cb091599

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-02-26

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Cisco Talos identified the UAT-10027 campaign (active since at least Dec 2025) targeting U.S. education and healthcare to deploy a novel 64-bit backdoor called Dohdoor. Initial access likely involves phishing that triggers PowerShell to download a batch and a malicious DLL that is sideloaded into legitimate binaries; Dohdoor uses DNS-over-HTTPS (Cloudflare), custom XOR-SUB decryption, process hollowing, and syscall trampoline techniques to fetch and execute encrypted payloads (telemetry shows Cobalt Strike as a follow-on). Talos notes technical overlap with Lazarus tradecraft and assesses low-confidence attribution to North Korea while documenting detailed TTPs and persistence/evasion behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.