UAT-10027 is a previously undocumented threat activity cluster tracked for an ongoing campaign active since at least December 2025. The actor has targeted organizations in the United States, particularly in the education and healthcare sectors, to deploy a custom Windows backdoor and loader known as Dohdoor. Initial access is assessed to likely involve phishing or other social-engineering lures that trigger a multi-stage infection chain using PowerShell and batch-script staging. The actor’s tradecraft emphasizes stealth and defense evasion. UAT-10027 has used DLL sideloading with legitimate Microsoft-signed binaries, living-off-the-land utilities, anti-forensic cleanup, process hollowing, and in-memory execution of follow-on payloads. Dohdoor resolves command-and-control infrastructure through DNS-over-HTTPS and then communicates over HTTPS, blending malicious traffic with normal encrypted web activity and reducing the effectiveness of traditional DNS-based monitoring. The malware also uses hash-based API resolution, custom payload decryption, and NTDLL syscall unhooking or patching to bypass endpoint monitoring based on user-mode hooks. Telemetry and analysis indicate Dohdoor can retrieve and execute additional payloads directly in memory, and follow-on activity has been assessed as likely involving Cobalt Strike. The campaign has been characterized as deliberate and persistent, with operators seeking covert footholds in victim environments rather than immediate disruption. Attribution remains unconfirmed. A North Korea nexus has been assessed only with low confidence based on technical overlaps with Lazarus-associated tradecraft, including similarities to Lazarloader, but the victimology differs from more typical Lazarus targeting patterns. The dominant assessed motivation is financial, based on the observed victimology and reporting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a malware campaign using the Dohdoor backdoor against U.S. education and healthcare organizations, leveraging DNS-over-HTTPS via Cloudflare for covert command-and-control and using phishing, DLL sideloading, process hollowing, and in-memory payload delivery.
Cluster targeting US education and healthcare to deploy the Dohdoor backdoor using DNS-over-HTTPS for C2; observed use of what appears to be Cobalt Strike Beacon; assessed as likely financially motivated based on victimology.
Threat cluster targeting U.S. education and healthcare to deploy the Dohdoor backdoor; uses DNS-over-HTTPS for C2 and reflective payload execution; observed follow-on use consistent with Cobalt Strike and assessed as likely financially motivated.
Campaign targeting U.S. education and healthcare organizations using the Dohdoor backdoor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.