The Containment Era is here. →Explore

Executive Summary

In December 2025, the threat actor group UAT-10027 initiated a sophisticated cyber campaign targeting the U.S. education and healthcare sectors. The attackers employed a novel backdoor named Dohdoor, which utilizes DNS-over-HTTPS (DoH) for covert command-and-control communications, effectively evading traditional network monitoring tools. The initial infection vector is suspected to involve phishing emails that execute PowerShell scripts, leading to the download and execution of malicious DLLs via DLL side-loading techniques. These DLLs facilitate the deployment of additional payloads, such as Cobalt Strike Beacons, directly into the memory of compromised systems. The campaign's use of legitimate Windows processes and encrypted communications poses significant challenges for detection and mitigation. (thehackernews.com)

This incident underscores a growing trend of advanced persistent threats (APTs) leveraging encrypted communication channels like DoH to conceal malicious activities. The targeting of critical sectors such as education and healthcare highlights the urgent need for enhanced cybersecurity measures and vigilance against sophisticated attack vectors. (thehackernews.com)

Why This Matters Now

The UAT-10027 campaign exemplifies the increasing sophistication of cyber threats, particularly the use of encrypted channels like DNS-over-HTTPS to evade detection. As attackers continue to refine their techniques, organizations, especially in critical sectors, must adopt proactive security measures to detect and mitigate such covert operations. (thehackernews.com)

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Dohdoor is a backdoor malware that utilizes DNS-over-HTTPS for command-and-control communications, allowing attackers to covertly manage infected systems and deploy additional payloads. ([thehackernews.com](https://thehackernews.com/2026/02/uat-10027-targets-us-education-and.html?utm_source=openai))

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and identity-aware policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While Aviatrix CNSF may not prevent the initial phishing attack, it could likely limit the attacker's ability to exploit the compromised system by enforcing strict segmentation and identity-aware policies.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Aviatrix Zero Trust Segmentation could likely limit the attacker's ability to escalate privileges by enforcing strict access controls and isolating workloads.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Aviatrix East-West Traffic Security could likely limit the attacker's ability to move laterally by monitoring and controlling internal traffic flows.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Aviatrix Multicloud Visibility & Control could likely limit the attacker's ability to maintain command-and-control channels by providing comprehensive monitoring and policy enforcement across cloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Aviatrix Egress Security & Policy Enforcement could likely limit the attacker's ability to exfiltrate data by controlling and monitoring outbound traffic.

Impact (Mitigations)

Aviatrix Zero Trust CNSF could likely limit the potential impact of the attack by reducing the attacker's ability to access critical systems and data.

Impact at a Glance

Affected Business Functions

  • Student Information Systems
  • Electronic Health Records (EHR)
  • Administrative Operations
  • Research Data Management
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of student and patient personal information, including names, addresses, medical records, and academic records.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of potential threats within the network.
  • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration and command-and-control communications.
  • Utilize Threat Detection & Anomaly Response systems to identify and respond to suspicious activities, such as unusual PowerShell executions or DLL sideloading attempts.
  • Enhance Multicloud Visibility & Control to gain comprehensive insights into network traffic and detect anomalies across cloud environments.
  • Apply Inline IPS (Suricata) to inspect and block known exploit patterns and malicious payloads, reducing the risk of initial compromise and subsequent stages of the attack.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image