UAT-10027 Targets U.S. Education and Healthcare with Dohdoor Backdoor
ID: 27e367f5-ddeb-58de-b0b5-4a7b6867bb2a
STIX ID: report--27e367f5-ddeb-58de-b0b5-4a7b6867bb2a
Feed Name: The Hacker News
Threat Score
**Executive Summary:** Cisco Talos has identified an active campaign (UAT-10027) targeting U.S. education and healthcare organizations since December 2025 that delivers a novel backdoor called Dohdoor; the malware uses DoH for C2, DLL side‑loading with legitimate executables, reflective in-memory payload execution (Cobalt Strike observed), and user-mode unhooking to evade EDR, with payloads named like "propsys.dll" and "batmeter.dll" and C2 infrastructure hidden behind Cloudflare.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
