INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

UAT-10027 Targets U.S. Education and Healthcare with Stealthy Dohdoor Backdoor

| 2026-02-26 19:10 CRITICAL MEDIUM
Executive Summary AI-generated
The Talos team has identified a new threat cluster, tracked as UAT-10027, targeting US education and healthcare organizations since at least December 2025 to deploy a previously unseen backdoor named Dohdoor. This campaign deviates from the Lazarus Group's typical profile of cryptocurrency and defense-targeting, instead focusing on these sectors. The attackers used PowerShell to run curl with an encoded URL, downloading a malicious batch file likely delivered through phishing, which was then sideloaded using legitimate Windows executables. A 64-bit DLL loader, Dohdoor, was deployed in November 2025, allowing the attackers to download and decrypt payloads inside legitimate Windows processes. The malware resolves Windows APIs through hash-based lookups, parses command-line arguments from the sideloaded executable, and extracts C2 URLs and payload paths. To evade EDR, Dohdoor locates ntdll.dll and checks NtProtectVirtualMemory for potential vulnerabilities. This new threat cluster highlights the overlaps in victimology between UAT-10027 and other North Korean APTs, such as those targeting healthcare and education sectors using Maui ransomware or Kimsuky targeting education sectors.
Technical Mitigations AI-generated
* Implement a secure patching mechanism for Windows systems to detect and prevent the use of NTDLL unhooking, which is used by Dohdoor to evade EDR (Exploitation Detection and Response) detection. * Use a secure communication protocol such as TLS 1.3 or higher to encrypt all data transmitted between clients and servers in the UAT-10027 campaign, making it more difficult for attackers to intercept and decrypt sensitive information. * Regularly update and patch Windows systems to ensure that any known vulnerabilities are addressed before they can be exploited by attackers using Dohdoor. * Implement a robust anti-malware solution with advanced threat detection capabilities to identify and block malicious payloads like Dohdoor, including those used in follow-on payload attacks such as the use of Cobalt Strike Beacons.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Lazarus GroupLazarus GroupKimsukyKimsuky Cobalt StrikeCobalt Strike
Target & Sectors
Global Scope healthcarehealthcare defensedefense healthhealth educationeducation
Incident Timeline
November 2025
The threat actors used a Cobalt Strike Beacon as the follow-on payload to target U.S. education and healthcare sectors with stealthy Dohdoor backdoors.
infrastructure Windows
general_metric 64 bit
organisation Lazarus Group
organisation APT
threat_actor Kimsuky
threat_actor Lazarus Group
organisation byte
data_breach 6 byte
organisation EDR
organisation HTTPS GET
organisation XOR-SUB
data_breach 16 byte
organisation Single Instruction,
organisation Multiple Data
data_breach 32 first bytes
organisation NTDLL
organisation SecurityAffairs
at least December 2025
Threat actors used a previously undisclosed backdoor called Dohdoor to deploy the T1588.001 malware on U.S. education and healthcare organizations since at least December 2025.
industry Education
industry Healthcare
tactic T1588.001 - Malware
general_metric 26  Feb
December 2025
Threat actors used PowerShell to run curl with an encoded URL, downloading a malicious batch file named Dohdoor via sideloading from compromised Cloudflare infrastructure.
organisation DLL
infrastructure Windows
organisation ProgramData
organisation Public
organisation DNS
organisation Cloudflare
organisation HTTPS
February 26, 2026
Threat actors used a stealthy Dohdoor backdoor to deploy a new threat on the U.S. education and healthcare sectors during the General Document Context of Incident UAT-10027 campaign.
industry Education
industry Healthcare
Feb 26, 2026
Threat actors used Dohdoor to deploy a stealthy backdoor in the U.S. education and healthcare sectors via compromised General Dynamics Information Technology systems.
2026-02-26
Threat actors used Dohdoor to target U.S. education and healthcare with stealthy backdoors through DNS-over-HTTPS (DoH) communications, leveraging a Cobalt Strike Beacon payload.
organisation APT
threat_actor Kimsuky
organisation Dohdoor
organisation Healthcare
organisation UAT-10027 Targets U.S. Education
organisation Dohdoor Backdoor
threat_actor Lazarus Group
organisation DLL
infrastructure Windows
organisation Fondue.exe
organisation UAT-10027
organisation EDR
organisation DNS
organisation Chetan Raghuprasad
organisation The Hacker News
organisation Cloudflare
organisation IP
Tactical Metrics
Metrics
infrastructure
​Windows
Affected Product
Metrics
data_breach
6
Byte
Metrics
data_breach
16
Byte
Metrics
data_breach
32
First Bytes
Intelligence Sources