UAT-10027

2026-02-26 • Cisco TalosNew Dohdoor malware campaign targets education an…

UAT-10027 is a designation Cisco Talos uses for a threat actor behind an ongoing campaign, observed since at least December 2025, that targets education and healthcare organizations in the United States with a previously undisclosed backdoor Talos named Dohdoor. The multi-stage intrusion chain begins with likely phishing-delivered PowerShell and batch scripts that side-load a malicious DLL disguised as a legitimate Windows library, using living-off-the-land binaries and command-and-control infrastructure hidden behind reputable cloud services to evade detection. Dohdoor uses DNS-over-HTTPS to resolve its command-and-control domains, employs custom encryption for its payloads, and reflectively injects decrypted payloads, potentially including Cobalt Strike, into legitimate Windows processes while bypassing endpoint detection through system-call unhooking. Talos assessed with low confidence that UAT-10027 has a North Korea nexus, citing technical overlaps with a tool called Lazarloader used by the Lazarus Group, while noting the campaign's education and healthcare targeting diverges from Lazarus's more typical cryptocurrency and defense focus.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster