UAT-10027 campaign hits U.S. education and healthcare with stealthy Dohdoor backdoor
ID: 820b049e-e67b-575c-8cfb-3b75cb091599
STIX ID: report--820b049e-e67b-575c-8cfb-3b75cb091599
Feed Name: Security Affairs
Cisco Talos identified the UAT-10027 campaign (active since at least Dec 2025) targeting U.S. education and healthcare to deploy a novel 64-bit backdoor called Dohdoor. Initial access likely involves phishing that triggers PowerShell to download a batch and a malicious DLL that is sideloaded into legitimate binaries; Dohdoor uses DNS-over-HTTPS (Cloudflare), custom XOR-SUB decryption, process hollowing, and syscall trampoline techniques to fetch and execute encrypted payloads (telemetry shows Cobalt Strike as a follow-on). Talos notes technical overlap with Lazarus tradecraft and assesses low-confidence attribution to North Korea while documenting detailed TTPs and persistence/evasion behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
