logo

Dohdoor Malware Targets U.S. Schools and Healthcare with Multi-Stage Attack

ID: 66c51557-0fbe-59af-b6c1-7dc6af26f260

STIX ID: report--66c51557-0fbe-59af-b6c1-7dc6af26f260

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-02-27

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A multi-stage campaign (UAT-10027) is actively deploying the Dohdoor backdoor against U.S. schools and healthcare providers to establish persistent access and stage Cobalt Strike beacons; the malware uses phishing-triggered PowerShell downloaders, DLL sideloading of malicious DLLs via trusted binaries, process hollowing, DoH-based C2 over Cloudflare, and advanced EDR-evasion techniques, with telemetry and IoCs provided and a low-confidence link to Lazarus.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.