New Dohdoor malware campaign targets education and health care
2026-02-26 • Cisco Talos •
https://blog.talosintelligence.com/new-dohdoor-malware-campaign/
Cisco Talos reports an ongoing campaign by UAT-10027 that has delivered a previously undisclosed backdoor named Dohdoor since at least December 2025. The campaign targeted education and health care organizations, predominantly in the United States, through a likely phishing-led chain involving PowerShell, remote batch scripts, DLL sideloading, and anti-forensic cleanup. Dohdoor resolves C2 domains through DNS-over-HTTPS to Cloudflare DNS, communicates over HTTPS to Cloudflare-fronted infrastructure, and can download, decrypt, and reflectively execute payloads such as a potential Cobalt Strike Beacon inside legitimate Windows processes. The malware also uses API hashing, encrypted communications, process hollowing, and EDR bypass techniques, making the campaign relevant for defenders monitoring trusted-cloud C2 abuse and LOLBin-based execution chains.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7ff31977972c224a76155d13b6d685e3 | 2026-02-26 | 2026-02-26 |
| HASH | 466556e923186364e82cbdb4cad8df2c | 2026-02-26 | 2026-02-26 |