Rescana
Dohdoor Backdoor Attack Targets U.S. Education and Healthcare Sectors
First seen 26 Feb 2026, 22:13 UTC
•



+2
•79% similarity
•41.1
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The UAT-10027 cyber campaign has been identified as targeting the U.S. education and healthcare sectors since at least December 2025. This campaign deploys a novel backdoor named Dohdoor, utilizing DNS-over-HTTPS for covert communications and employing advanced techniques such as DLL sideloading and process hollowing to evade detection. Initial access is likely gained through phishing attacks.
ThreatCluster AI
How this analysis works
Timeline
2025-12-01
UAT-10027 campaign begins targeting sectors
2026-02-26
Dohdoor backdoor identified by Cisco Talos