logo

Dohdoor: The Stealthy New Backdoor Targeting U.S. Education and Healthcare

ID: 6000ccb1-33f0-57fa-b632-fcb0a6a2340a

STIX ID: report--6000ccb1-33f0-57fa-b632-fcb0a6a2340a

Feed Name: NoHackie

Threat Score
82/100

Date Published: 2026-02-01

Date Updated: 2026-04-19

...
...

Cisco Talos researchers describe the Dohdoor campaign (UAT-10027), a sophisticated 64-bit backdoor observed since December 2025 targeting U.S. education and healthcare; Dohdoor uses DLL sideloading with legitimate signed binaries, DNS-over-HTTPS via Cloudflare for covert C2, syscall unhooking to bypass EDR, process hollowing and a custom XOR-SUB decryption routine, and likely acts as a loader for Cobalt Strike — IOCs, MITRE ATT&CK mappings, and detection recommendations are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.