BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New DoH Backdoor Targets US Education & Healthcare

U.S. education and healthcare targeted by Dohdoor backdoor using stealthy DoH tunneling.

  • A new cyber-espionage campaign, UAT-10027, is actively targeting U.S. education and healthcare organizations.
  • The attackers deploy a previously unseen backdoor called Dohdoor, which uses DNS-over-HTTPS (DoH) to hide its communications.
  • While some technical overlaps with the North Korean Lazarus Group exist, the victim profile represents a potential shift in tactics.

A previously undocumented threat actor group has been deploying a new backdoor against the U.S. education and healthcare sectors since at least December 2025. Cisco Talos researchers track this activity cluster as UAT-10027, with a final payload named Dohdoor.

- Advertisement -

This novel malware utilizes DNS-over-HTTPS (DoH) for command-and-control, effectively disguising its traffic as legitimate web activity. Consequently, the backdoor can bypass traditional DNS-based security tools while downloading and executing further malicious code directly into a victim’s memory.

The initial infection chain likely begins with a phishing email that executes a PowerShell script. That script subsequently downloads a batch file from a remote server, leading to the final malicious DLL payload.

Attackers then use a legitimate Windows executable to load the Dohdoor DLL via DLL side-loading techniques. The infected system connects to command servers hidden behind the Cloudflare infrastructure for stealth.

Dohdoor also employs advanced evasion tactics, such as unhooking system calls to bypass endpoint detection. Meanwhile, analysts noted tactical similarities between Dohdoor and the Lazarloader downloader previously linked to the North Korean Lazarus Group.

- Advertisement -

However, UAT-10027’s focus on healthcare and education deviates from Lazarus’s typical cryptocurrency or defense targets. North Korean groups like Kimsuky have previously targeted the education sector, however, highlighting a possible overlap in victimology.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Oracle E-Business Flaw Actively Exploited

A critical flaw in Oracle Payments (CVE-2026-46817) is being actively exploited to take over...

Tommy Robinson’s son behind his ‘patriotic’ crypto token

British activist Tommy Robinson shilled his son's "Patriotic Bull" cryptocurrency token on X before...

AI Browser Extension Intercepted User Searches

A malicious Chrome extension impersonating the AI search engine Perplexity intercepted and logged user...

Saylor’s MicroStrategy to Sell Bitcoin Amid Crypto Slump

Strategy announced a new program authorizing the sale of up to $1.25 billion worth...

$3.7B in Stablecoins Frozen by Censorship

Tether and Circle have frozen approximately $3.7 billion in stablecoins on the Ethereum and...

Must Read

What Are Anonymous Debit Cards And How Do They Work?

You've heard about anonymous debit cards, but what are they really? Anonymous Debit Cards are cards that let you make purchases without revealing your...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading