US Educational and Healthcare Facilities Under Attack

US Educational Entities Under Active Targeted Attack

Cisco Talos has identified an ongoing attack sequence against US based education and healthcare entities since December of 2025.  The attack group is known as “UAT-10027” alleged to be a North Korean threat group. 

The attacks involved a piece of malware called “Dohdoor.”  Dohdoor is a backdoor malware, it uses DNS-over-HTTPS (DOH) technique to allow command and control (C2) communications.  Along with that communication vector the malware also allows attackers to download and execute other pieces of malware onto the infected systems. 

The attackers have also been seen utilizing “living off the land” (LOLbins) to sideload the Dohdoor malware.  Their communications seem to be running through reputable cloud services, such as Cloudflare and others, to help aid them in their communication. 

View Post↗

Fig. 1 Talos Diagram

This is a legitimate and ongoing attack against the identified businesses and entities.  If you are employed at an educational or healthcare entity, then please share this with your IT and Security staff to ensure awareness and proper protections are in place to protect your data.

Thankfully, Talos has provided a list of indicators of compromise (IOCs) at their Github site as well. 

54e18978c6405f56cd59ba55a62291436639f21cf325ae509f0599b15e8f7f53

0bb130b1fafb17705d31fe5dd25e7b2d62176578609d75cc57911ef5582ef17a

54545fa3a2d8da6746021812ebaa9d26f33bba4f63c6f7f35caa6fa4ee8c0e6a

8e97c677aec905152f8a92fed50bb84ef2e8985d5c29330c5a05a4a2afcbd4a5

800faaf15d5f42f2ab2c1d2b6b65c8a9e4def6dc10f6ce4e269dcf23f4e8dae2

b1bd8f7d4488977cca03954a57f5c8ad7bfd4609bcc3bae92326830fcbd3232c

2ce3e75997f89b98dd280d164a5f21f7565f4de26eed61243badde04b480700e

CJiTDrpwnnA[.]MswINsoFTUPDLoad[.]deSigN

LBaNDUgZCFG[.]deepInspectiOnSYSTEM[.]oNLiNE

LsyPdQGXrEDfPx[.]MSwInSofTUpDloAd[.]dESign

YHDJTyLNsMWVuU[.]DEEPinSPeCTioNsyStEM[.]OnLiNe

SDXsIol[.]PNUIsckmHwAgzVdYJRlbeFT[.]SoftWarE

EzQrvkFgEJWCTDNc[.]pNuiSCKMhwAgZvdyjrlBEFT[.]softwarE

txjIQslrRIg[.]MSwINSOFTUPDLoaD[.]DesiGN

QHtcKZBXtKdVyr[.]mSWinSoFTUpdLOAD[.]DeSIgn

GITkzxd[.]pNUIScKMhWAgZvdyJRlBEFT[.]SoFtwaRE

GppiwoGwNdiakkDU[.]pnuiSckMHwaGzvDYjRLbeFt[.]SoFTWARe

hxxp[://]gITkzxd[.]pNUIScKMhWAgZvdyJRlBEFT[.]SoFtwaRE/X111111

hxxp[://]GppiwoGwNdiakkDU[.]pnuiSckMHwaGzvDYjRLbeFt[.]SoFTWARe/111111?sub=s

hxxp[://]lBaNDUgZCFG[.]deepInspectiOnSYSTEM[.]oNLiNE/X111111

hxxp[://]CJiTDrpwnnA[.]MswINsoFTUPDLoad[.]deSigN/x111111

hxxp[://]LsyPdQGXrEDfPx[.]MSwInSofTUpDloAd[.]dESign/111111?sub=s

hxxp[://]sDXsIol[.]PNUIsckmHwAgzVdYJRlbeFT[.]SoftWarE/X111111

hxxp[://]ezQrvkFgEJWCTDNc[.]pNuiSCKMhwAgZvdyjrlBEFT[.]softwarE/111111?sub=d

hxxp[://]lLalWpIJnjskClwY[.]PnUiscKMhWaGzVdyJRlBEfT[.]SofTWaRe/111111?sub=s

Below is just one image from the hashes provided by Talos, which shows a small identification for the malware utilized in this attack.

Fig. 2 Virus Total Lookup

Being aware of such ongoing campaigns is vital to protecting your networks and data.  Go forth and conquer! 

Sources:  https://github.com/Cisco-Talos/IOCs/blob/main/2026/02/new-dohdoor-malware-campaign.txt

https://blog.talosintelligence.com/new-dohdoor-malware-campaign

https://www.virustotal.com/gui/file/54e18978c6405f56cd59ba55a62291436639f21cf325ae509f0599b15e8f7f53

Leave a Reply

Discover more from Dave Does Cyber Security

Subscribe now to keep reading and get access to the full archive.

Continue reading