#Dohdoor
Malware/Tool
Dohdoor is a Windows backdoor delivered by UAT-10027 in a campaign targeting United States education and health care organizations since at least December 2025. Likely phishing-led initial access triggered a PowerShell script and downloaded batch script, which retrieved a malicious DLL disguised as a legitimate Windows file. The actor sideloaded Dohdoor through a legitimate executable. Once active, it used DNS-over-HTTPS with Cloudflare DNS to resolve command-and-control domains, then established an HTTPS tunnel to the Cloudflare edge network. Dohdoor can also download and reflectively execute additional binary payloads, while cloud services and living-off-the-land executables supported stealthy operation.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days