Dohdoor Malware: New Backdoor Targets U.S. Education & Healthcare (UAT-10027)
Feb 26 · 5 min read · Cisco Talos has disclosed a previously unknown backdoor called Dohdoor, deployed by threat activity cluster UAT-10027 against U.S. education and healthcare organizations since December 2025. The malware uses DNS-over-HTTPS (DoH) to resolve C2 domains...
Join discussion



