New Dohdoor malware campaign targets education and health care

2026-02-26 Cisco Talos

https://blog.talosintelligence.com/new-dohdoor-malware-campaign/

Thumbnail for New Dohdoor malware campaign targets education and health care

Cisco Talos reports an ongoing campaign by UAT-10027 that has delivered a previously undisclosed backdoor named Dohdoor since at least December 2025. The campaign targeted education and health care organizations, predominantly in the United States, through a likely phishing-led chain involving PowerShell, remote batch scripts, DLL sideloading, and anti-forensic cleanup. Dohdoor resolves C2 domains through DNS-over-HTTPS to Cloudflare DNS, communicates over HTTPS to Cloudflare-fronted infrastructure, and can download, decrypt, and reflectively execute payloads such as a potential Cobalt Strike Beacon inside legitimate Windows processes. The malware also uses API hashing, encrypted communications, process hollowing, and EDR bypass techniques, making the campaign relevant for defenders monitoring trusted-cloud C2 abuse and LOLBin-based execution chains.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7ff31977972c224a76155d13b6d685e3 2026-02-26 2026-02-26
HASH 466556e923186364e82cbdb4cad8df2c 2026-02-26 2026-02-26

Related Actors

« Back