UAT-10027
2026-02-26 • Cisco Talos • New Dohdoor malware campaign targets education an…
UAT-10027 is a designation Cisco Talos uses for a threat actor behind an ongoing campaign, observed since at least December 2025, that targets education and healthcare organizations in the United States with a previously undisclosed backdoor Talos named Dohdoor. The multi-stage intrusion chain begins with likely phishing-delivered PowerShell and batch scripts that side-load a malicious DLL disguised as a legitimate Windows library, using living-off-the-land binaries and command-and-control infrastructure hidden behind reputable cloud services to evade detection. Dohdoor uses DNS-over-HTTPS to resolve its command-and-control domains, employs custom encryption for its payloads, and reflectively injects decrypted payloads, potentially including Cobalt Strike, into legitimate Windows processes while bypassing endpoint detection through system-call unhooking. Talos assessed with low confidence that UAT-10027 has a North Korea nexus, citing technical overlaps with a tool called Lazarloader used by the Lazarus Group, while noting the campaign's education and healthcare targeting diverges from Lazarus's more typical cryptocurrency and defense focus.
-
61
Related Actors
-
691
Related Reports