Executive Summary
In December 2025, the threat actor group UAT-10027 initiated a sophisticated cyber campaign targeting the U.S. education and healthcare sectors. The attackers employed a novel backdoor named Dohdoor, which utilizes DNS-over-HTTPS (DoH) for covert command-and-control communications, effectively evading traditional network monitoring tools. The initial infection vector is suspected to involve phishing emails that execute PowerShell scripts, leading to the download and execution of malicious DLLs via DLL side-loading techniques. These DLLs facilitate the deployment of additional payloads, such as Cobalt Strike Beacons, directly into the memory of compromised systems. The campaign's use of legitimate Windows processes and encrypted communications poses significant challenges for detection and mitigation. (thehackernews.com)
This incident underscores a growing trend of advanced persistent threats (APTs) leveraging encrypted communication channels like DoH to conceal malicious activities. The targeting of critical sectors such as education and healthcare highlights the urgent need for enhanced cybersecurity measures and vigilance against sophisticated attack vectors. (thehackernews.com)
Why This Matters Now
The UAT-10027 campaign exemplifies the increasing sophistication of cyber threats, particularly the use of encrypted channels like DNS-over-HTTPS to evade detection. As attackers continue to refine their techniques, organizations, especially in critical sectors, must adopt proactive security measures to detect and mitigate such covert operations. (thehackernews.com)
Attack Path Analysis
The UAT-10027 campaign began with phishing emails containing malicious PowerShell scripts, leading to the download and execution of a Windows batch script. This script facilitated the download of a malicious DLL, which was executed via DLL sideloading using legitimate Windows executables. The backdoor, Dohdoor, established command-and-control communication through DNS-over-HTTPS, allowing the attackers to download and execute additional payloads, including Cobalt Strike Beacons. While no data exfiltration has been observed, the attackers have maintained persistent access, indicating potential for future exfiltration or disruptive actions.
Kill Chain Progression
Initial Compromise
Description
The attackers likely gained initial access through phishing emails containing malicious PowerShell scripts, leading to the execution of a Windows batch script that downloaded a malicious DLL.
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
Command and Scripting Interpreter: PowerShell
Hijack Execution Flow: DLL Side-Loading
Application Layer Protocol: DNS
Process Injection
Impair Defenses: Disable or Modify Tools
Ingress Tool Transfer
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure security patches are installed within one month of release
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement network segmentation and monitoring
Control ID: Pillar 3: Network and Environment
NIS2 Directive – Incident Handling
Control ID: Article 21
HIPAA – Risk Analysis
Control ID: 164.308(a)(1)(ii)(A)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Higher Education/Acadamia
Universities face critical backdoor threats via DNS-over-HTTPS C2 communications, bypassing traditional network security with interconnected institutional attack surfaces requiring enhanced egress filtering.
Health Care / Life Sciences
Healthcare facilities including elderly care targeted by Dohdoor malware exploiting HIPAA-regulated environments through DLL side-loading and EDR evasion techniques threatening patient data.
Computer/Network Security
Security infrastructure challenged by DNS-over-HTTPS C2 communications bypassing detection systems, requiring enhanced threat detection capabilities and zero trust segmentation for client protection.
Government Administration
Public sector education and healthcare oversight agencies face supply chain risks from interconnected institutional compromises potentially enabling lateral movement across government-affiliated networks.
Sources
- UAT-10027 Targets U.S. Education and Healthcare with Dohdoor Backdoorhttps://thehackernews.com/2026/02/uat-10027-targets-us-education-and.htmlVerified
- New Dohdoor malware campaign targets education and health carehttps://blog.talosintelligence.com/new-dohdoor-malware-campaign/Verified
- UAT-10027 campaign hits U.S. education and healthcare with stealthy Dohdoor backdoorhttps://securityaffairs.com/188558/apt/uat-10027-campaign-hits-u-s-education-and-healthcare-with-stealthy-dohdoor-backdoor.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent the initial phishing attack, it could likely limit the attacker's ability to exploit the compromised system by enforcing strict segmentation and identity-aware policies.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could likely limit the attacker's ability to escalate privileges by enforcing strict access controls and isolating workloads.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could likely limit the attacker's ability to move laterally by monitoring and controlling internal traffic flows.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could likely limit the attacker's ability to maintain command-and-control channels by providing comprehensive monitoring and policy enforcement across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could likely limit the attacker's ability to exfiltrate data by controlling and monitoring outbound traffic.
Aviatrix Zero Trust CNSF could likely limit the potential impact of the attack by reducing the attacker's ability to access critical systems and data.
Impact at a Glance
Affected Business Functions
- Student Information Systems
- Electronic Health Records (EHR)
- Administrative Operations
- Research Data Management
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of student and patient personal information, including names, addresses, medical records, and academic records.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of potential threats within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration and command-and-control communications.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to suspicious activities, such as unusual PowerShell executions or DLL sideloading attempts.
- • Enhance Multicloud Visibility & Control to gain comprehensive insights into network traffic and detect anomalies across cloud environments.
- • Apply Inline IPS (Suricata) to inspect and block known exploit patterns and malicious payloads, reducing the risk of initial compromise and subsequent stages of the attack.



