Cisco Talos reported an ongoing intrusion campaign, tracked as UAT-10027, targeting U.S. education and healthcare organizations since at least December 2025 to deploy a previously undocumented backdoor dubbed Dohdoor. The activity is assessed to begin with likely social-engineering/phishing that leads to execution of a PowerShell script, which then pulls a Windows batch script from a remote staging server; the batch script downloads a malicious DLL (reported as propsys.dll or batmeter.dll) and executes it via DLL side-loading using legitimate Windows executables (e.g., Fondue.exe, mblctr.exe, ScreenClippingHost.exe) and other living-off-the-land binaries (LOLBins).
Once running, Dohdoor uses DNS-over-HTTPS (DoH) for command-and-control and can reflectively download and execute additional payloads. Talos assessed that the backdoor is used to retrieve a next-stage payload directly into memory, including a Cobalt Strike Beacon, while the operator obscures C2 by placing infrastructure behind reputable services such as Cloudflare—making outbound traffic appear as legitimate HTTPS to trusted IP space and reducing the effectiveness of DNS-based detections, sinkholing, and domain-lookup monitoring.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
On February 26, 2026, Cisco Talos published research on the ongoing UAT-10027 campaign, detailing Dohdoor's use of DNS-over-HTTPS through Cloudflare, EDR bypass via NTDLL unhooking, and anti-forensic behavior. Talos also released detection coverage including ClamAV signatures, Snort rules, and IOCs through a GitHub repository.
In its investigation, Cisco Talos found telemetry and OSINT indicators suggesting the final payload may be a Cobalt Strike Beacon. Talos also assessed with low confidence that UAT-10027 may have North Korea nexus due to tradecraft overlaps with Lazarus tooling such as Lazarloader, while noting the victimology differs from typical Lazarus targeting.
The campaign uses likely phishing or social-engineering for initial access, followed by PowerShell and batch-script stages that sideload malicious DLLs through legitimate Windows binaries. The previously undisclosed Windows backdoor/loader, Dohdoor, then downloads and decrypts follow-on payloads and executes them in memory via process hollowing.
Cisco Talos said the malicious campaign tracked as UAT-10027 has been active since at least December 2025, primarily targeting U.S. education and healthcare organizations. Reported victims include multiple educational institutions and at least one healthcare or elderly-care facility.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcego.theregister.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.