#Dohdoor

Malware/Tool

2026-02-26 • New Dohdoor malware campaign targets education and health care

Dohdoor is a Windows backdoor delivered by UAT-10027 in a campaign targeting United States education and health care organizations since at least December 2025. Likely phishing-led initial access triggered a PowerShell script and downloaded batch script, which retrieved a malicious DLL disguised as a legitimate Windows file. The actor sideloaded Dohdoor through a legitimate executable. Once active, it used DNS-over-HTTPS with Cloudflare DNS to resolve command-and-control domains, then established an HTTPS tunnel to the Cloudflare edge network. Dohdoor can also download and reflectively execute additional binary payloads, while cloud services and living-off-the-land executables supported stealthy operation.

Tagged Reports

« Back