US Educational Entities Under Active Targeted Attack
Cisco Talos has identified an ongoing attack sequence against US based education and healthcare entities since December of 2025. The attack group is known as “UAT-10027” alleged to be a North Korean threat group.
The attacks involved a piece of malware called “Dohdoor.” Dohdoor is a backdoor malware, it uses DNS-over-HTTPS (DOH) technique to allow command and control (C2) communications. Along with that communication vector the malware also allows attackers to download and execute other pieces of malware onto the infected systems.
The attackers have also been seen utilizing “living off the land” (LOLbins) to sideload the Dohdoor malware. Their communications seem to be running through reputable cloud services, such as Cloudflare and others, to help aid them in their communication.

Fig. 1 Talos Diagram
This is a legitimate and ongoing attack against the identified businesses and entities. If you are employed at an educational or healthcare entity, then please share this with your IT and Security staff to ensure awareness and proper protections are in place to protect your data.
Thankfully, Talos has provided a list of indicators of compromise (IOCs) at their Github site as well.
54e18978c6405f56cd59ba55a62291436639f21cf325ae509f0599b15e8f7f53
0bb130b1fafb17705d31fe5dd25e7b2d62176578609d75cc57911ef5582ef17a
54545fa3a2d8da6746021812ebaa9d26f33bba4f63c6f7f35caa6fa4ee8c0e6a
8e97c677aec905152f8a92fed50bb84ef2e8985d5c29330c5a05a4a2afcbd4a5
800faaf15d5f42f2ab2c1d2b6b65c8a9e4def6dc10f6ce4e269dcf23f4e8dae2
b1bd8f7d4488977cca03954a57f5c8ad7bfd4609bcc3bae92326830fcbd3232c
2ce3e75997f89b98dd280d164a5f21f7565f4de26eed61243badde04b480700e
CJiTDrpwnnA[.]MswINsoFTUPDLoad[.]deSigN
LBaNDUgZCFG[.]deepInspectiOnSYSTEM[.]oNLiNE
LsyPdQGXrEDfPx[.]MSwInSofTUpDloAd[.]dESign
YHDJTyLNsMWVuU[.]DEEPinSPeCTioNsyStEM[.]OnLiNe
SDXsIol[.]PNUIsckmHwAgzVdYJRlbeFT[.]SoftWarE
EzQrvkFgEJWCTDNc[.]pNuiSCKMhwAgZvdyjrlBEFT[.]softwarE
txjIQslrRIg[.]MSwINSOFTUPDLoaD[.]DesiGN
QHtcKZBXtKdVyr[.]mSWinSoFTUpdLOAD[.]DeSIgn
GITkzxd[.]pNUIScKMhWAgZvdyJRlBEFT[.]SoFtwaRE
GppiwoGwNdiakkDU[.]pnuiSckMHwaGzvDYjRLbeFt[.]SoFTWARe
hxxp[://]gITkzxd[.]pNUIScKMhWAgZvdyJRlBEFT[.]SoFtwaRE/X111111
hxxp[://]GppiwoGwNdiakkDU[.]pnuiSckMHwaGzvDYjRLbeFt[.]SoFTWARe/111111?sub=s
hxxp[://]lBaNDUgZCFG[.]deepInspectiOnSYSTEM[.]oNLiNE/X111111
hxxp[://]CJiTDrpwnnA[.]MswINsoFTUPDLoad[.]deSigN/x111111
hxxp[://]LsyPdQGXrEDfPx[.]MSwInSofTUpDloAd[.]dESign/111111?sub=s
hxxp[://]sDXsIol[.]PNUIsckmHwAgzVdYJRlbeFT[.]SoftWarE/X111111
hxxp[://]ezQrvkFgEJWCTDNc[.]pNuiSCKMhwAgZvdyjrlBEFT[.]softwarE/111111?sub=d
hxxp[://]lLalWpIJnjskClwY[.]PnUiscKMhWaGzVdyJRlBEfT[.]SofTWaRe/111111?sub=s
Below is just one image from the hashes provided by Talos, which shows a small identification for the malware utilized in this attack.

Fig. 2 Virus Total Lookup
Being aware of such ongoing campaigns is vital to protecting your networks and data. Go forth and conquer!
Sources: https://github.com/Cisco-Talos/IOCs/blob/main/2026/02/new-dohdoor-malware-campaign.txt
https://blog.talosintelligence.com/new-dohdoor-malware-campaign
https://www.virustotal.com/gui/file/54e18978c6405f56cd59ba55a62291436639f21cf325ae509f0599b15e8f7f53
Leave a Reply