logo

UAT-10027 Targets U.S. Education and Healthcare with Dohdoor Backdoor

ID: 27e367f5-ddeb-58de-b0b5-4a7b6867bb2a

STIX ID: report--27e367f5-ddeb-58de-b0b5-4a7b6867bb2a

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-02-26

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Executive Summary:** Cisco Talos has identified an active campaign (UAT-10027) targeting U.S. education and healthcare organizations since December 2025 that delivers a novel backdoor called Dohdoor; the malware uses DoH for C2, DLL side‑loading with legitimate executables, reflective in-memory payload execution (Cobalt Strike observed), and user-mode unhooking to evade EDR, with payloads named like "propsys.dll" and "batmeter.dll" and C2 infrastructure hidden behind Cloudflare.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.