logo

Dohdoor: New Stealth Backdoor Targets US Healthcare and Education

ID: 24816b79-03f9-5eff-93fb-8c299cf5d0a4

STIX ID: report--24816b79-03f9-5eff-93fb-8c299cf5d0a4

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-03-02

Date Updated: 2026-04-23

Author: Ddos

...
...

Cisco Talos researchers uncovered an ongoing, sophisticated espionage campaign (UAT-10027) deploying a novel DoH-based backdoor named "Dohdoor" that targets U.S. education and healthcare; the attack chain uses phishing to execute PowerShell and batch scripts, sideloads a malicious DLL (eg. "propsys.dll") into trusted applications, and leverages advanced evasion (Cloudflare DoH C2, process hollowing, NTDLL unhooking, reflective payload loading), with tradecraft similar to known North Korean APTs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.