UAT-10027 Targets U.S. Education and Healthcare with Dohdoor Backdoor

U.S. Education and Healthcare Under Siege: The Rise of Dohdoor and Stealthy Cyberattacks

A new, sophisticated malware campaign dubbed UAT-10027 is targeting U.S. Education and healthcare sectors, deploying a previously unknown backdoor named Dohdoor. This campaign, active since at least December 2025, highlights a growing trend of targeted attacks leveraging stealthy techniques to compromise critical infrastructure.

Dohdoor: A Deep Dive into the Technical Details

Dohdoor distinguishes itself through its use of DNS-over-HTTPS (DoH) for command-and-control (C2) communications. This technique masks malicious traffic as legitimate HTTPS traffic, bypassing traditional DNS-based detection systems and network monitoring tools. Researchers at Cisco Talos note that Dohdoor can also download and execute additional payloads reflectively, increasing its flexibility and potential impact.

The attack chain begins with suspected social engineering, likely phishing, leading to the execution of a PowerShell script. This script downloads a Windows batch script from a remote server, which then retrieves a malicious DLL – often disguised as “propsys.dll” or “batmeter.dll.” This DLL is loaded using DLL side-loading, a technique that exploits legitimate Windows executables like Fondue.exe, mblctr.exe, and ScreenClippingHost.exe to execute malicious code.

The Stealth Factor: Bypassing Security Measures

UAT-10027 employs several techniques to evade detection. Beyond DoH, Dohdoor unhooks system calls to bypass endpoint detection and response (EDR) solutions that rely on monitoring Windows API calls. The threat actors also hide their C2 servers behind Cloudflare infrastructure, further obscuring their activities and making them appear as legitimate traffic from trusted IP addresses.

Targeted Sectors and Potential Motives

The campaign has already impacted several educational institutions, including a university connected to others, expanding the potential attack surface. A healthcare facility specializing in elderly care has also been affected. Even as no data exfiltration has been observed yet, the victimology suggests a financially motivated attack. The initial payload observed is a Cobalt Strike Beacon, often used for establishing persistent access and further reconnaissance.

Possible Links to North Korean APTs

While the campaign is currently attributed to UAT-10027, Cisco Talos has identified technical similarities between Dohdoor and LazarusLoader, a downloader previously associated with the North Korean hacking group Lazarus. However, UAT-10027’s focus on education and healthcare differs from Lazarus’s typical targeting of cryptocurrency and defense industries. It’s key to note that other North Korean APT groups, such as Kimsuky, have previously targeted the education sector, and another group utilized Maui ransomware in the healthcare sector.

Future Trends in Targeted Malware Campaigns

The UAT-10027 campaign exemplifies several emerging trends in cybersecurity:

  • Increased Use of DoH: Expect to notice more malware leveraging DoH to evade detection and blend with legitimate network traffic.
  • Sophisticated Evasion Techniques: DLL side-loading and system call unhooking will likely grow more prevalent as attackers seek to bypass EDR solutions.
  • Targeted Attacks on Critical Infrastructure: Education and healthcare remain attractive targets due to their sensitive data and potential for disruption.
  • Blurring of APT Attribution: The technical overlaps between different threat actors make attribution increasingly challenging.
  • Expansion of Ransomware-as-a-Service: While not currently observed in this campaign, the potential for ransomware deployment remains a significant threat.

Pro Tip:

Regularly update your systems and security software. Implement multi-factor authentication (MFA) wherever possible, and educate your staff about phishing and social engineering tactics.

FAQ

What is Dohdoor? Dohdoor is a previously undocumented backdoor used in the UAT-10027 campaign to gain unauthorized access to systems.

Which sectors are being targeted? The U.S. Education and healthcare sectors are the primary targets of this campaign.

How does Dohdoor evade detection? Dohdoor uses techniques like DNS-over-HTTPS (DoH), DLL side-loading, and system call unhooking to bypass security measures.

Is there a link to North Korea? There are technical similarities between Dohdoor and malware used by the Lazarus Group, but a definitive link has not been established.

What can organizations do to protect themselves? Implement robust security measures, including regular updates, MFA, and employee training.

Did you know? The use of Cloudflare infrastructure to hide C2 servers is a common tactic employed by sophisticated threat actors to mask their activities.

Stay informed about the latest cybersecurity threats and best practices. Explore our other articles on malware analysis and threat intelligence to enhance your organization’s security posture. Subscribe to our newsletter for regular updates and insights.

Leave a Comment