Dohdoor: The Stealthy New Backdoor Targeting U.S. Education and Healthcare
ID: 6000ccb1-33f0-57fa-b632-fcb0a6a2340a
STIX ID: report--6000ccb1-33f0-57fa-b632-fcb0a6a2340a
Feed Name: NoHackie
Threat Score
Cisco Talos researchers describe the Dohdoor campaign (UAT-10027), a sophisticated 64-bit backdoor observed since December 2025 targeting U.S. education and healthcare; Dohdoor uses DLL sideloading with legitimate signed binaries, DNS-over-HTTPS via Cloudflare for covert C2, syscall unhooking to bypass EDR, process hollowing and a custom XOR-SUB decryption routine, and likely acts as a loader for Cobalt Strike — IOCs, MITRE ATT&CK mappings, and detection recommendations are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
