Dohdoor Backdoor Attack Targets U.S. Education and Healthcare Sectors

Dohdoor Backdoor Attack Targets U.S. Education and Healthcare Sectors

First seen 26 Feb 2026, 22:13 UTC Securityaffairs.CoRescanaLinkedinCybersecuritynewsScworld+2 79% similarity 41.1

Article Content

Browse articles
ThreatCluster

The UAT-10027 cyber campaign has been identified as targeting the U.S. education and healthcare sectors since at least December 2025. This campaign deploys a novel backdoor named Dohdoor, utilizing DNS-over-HTTPS for covert communications and employing advanced techniques such as DLL sideloading and process hollowing to evade detection. Initial access is likely gained through phishing attacks.

ThreatCluster AI How this analysis works

Timeline

2025-12-01
UAT-10027 campaign begins targeting sectors
2026-02-26
Dohdoor backdoor identified by Cisco Talos

Community

Browse all →

Tracked Entities in This Story