Threat reportMalwareTL-2026-0149

Dohdoor Backdoor — UAT-10027 DNS-over-HTTPS C2 Campaign Targeting US Education & Healthcare via Cloudflare Tunnel, DLL Sideloading, Cobalt Strike

highACTIVE

Dohdoor Backdoor (TL-2026-0149), also tracked as Dohdoor, is a high-severity malware campaign, first published 2026-02-26. It is attributed to UAT-10027 (North Korea) with low confidence, affects Microsoft Windows, maps to 19 MITRE ATT&CK techniques (T1003, T1027, T1036.005), and is covered by 9 detection rules and 16 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
1UAT-10027
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0149

Threat ID
TL-2026-0149
Also known as
Dohdoor
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
UAT-10027
Attribution confidence
LOW
Nation-state nexus
North Korea
Motivation
ESPIONAGE
Target sectors
education, healthcare
Target regions
United States
Detection rules
9
Indicators of compromise
16

Malware and tooling in Dohdoor Backdoor

Malware and tooling: Dohdoor, Cobalt Strike

How Dohdoor Backdoor works

Cisco Talos discovered UAT-10027 deploying a previously undisclosed backdoor called Dohdoor that uses DNS-over-HTTPS (DoH) via Cloudflare for C2 resolution and establishes HTTPS tunnels through Cloudflare edge infrastructure. The multi-stage attack chain targets US education and healthcare sectors through phishing, PowerShell downloaders, batch script droppers, and DLL sideloading of LOLBins (Fondue.exe, mblctr.exe, ScreenClippingHost.exe). Dohdoor reflectively loads Cobalt Strike Beacon into legitimate Windows processes via process hollowing. Low-confidence North Korea/Lazarus attribution based on shared XOR-SUB decryption constant (0x26) and NTDLL unhooking techniques.

Cisco Talos discovered an ongoing campaign by threat actor UAT-10027 active since at least December 2025. The campaign delivers a previously undisclosed backdoor dubbed Dohdoor that targets US education and healthcare sectors.

The multi-stage attack chain begins with social engineering phishing delivering a PowerShell script. The PowerShell executes curl.exe with an encoded URL to download a Windows batch file (.bat/.cmd). The batch script creates a hidden workspace in C:\ProgramData or C:\Users\Public, downloads a malicious DLL from the C2 server (via URL path /111111?sub=d), and disguises it as a legitimate Windows DLL — specifically propsys.dll or batmeter.dll. The script then copies legitimate Windows executables (Fondue.exe, mblctr.exe, ScreenClippingHost.exe) into the workspace folder and executes them, passing the C2 URL /111111?sub=s as a command-line argument. These legitimate executables sideload the malicious DLL. The batch script performs anti-forensic cleanup: deleting Run command history from RunMRU registry, clearing clipboard data, and self-deleting.

Dohdoor is a 64-bit DLL compiled November 25, 2025, with debug string 'C:\Users\diablo\Desktop\SimpleDll\TlsClient.hpp'. It dynamically resolves Windows APIs using hash-based lookups (avoiding static IAT detection). For C2 communication, Dohdoor employs DNS-over-HTTPS (DoH) via Cloudflare's DNS service — sending encrypted DNS queries over HTTPS port 443 with User-Agent 'insomnia/11.3.0' and Accept 'applications/dns-json'. It parses JSON responses by searching for 'Answer' and 'data' string patterns rather than using a full JSON parser.

The C2 infrastructure uses subdomain names mimicking Microsoft Windows software updates ('MswInSofTUpDloAd') and security appliances ('DEEPinSPeCTioNsyStEM'), with irregular capitalization across non-traditional TLDs (.OnLiNe, .DeSigN, .SoFTWARe). This capitalization strategy bypasses string-matching filters and provides infrastructure redundancy.

Dohdoor receives encrypted payloads using custom XOR-SUB decryption with a position-dependent cipher. The encrypted data has a 4:1 expansion ratio. Decryption uses SIMD vectorized processing for 16-byte blocks and a fallback formula: decrypted[i] = encrypted[i*4] - i - 0x26. The constant 0x26 is shared with Lazarus Group's Lazarloader tool.

Decrypted payloads are injected into legitimate Windows processes via process hollowing. Hardcoded targets: C:\Windows\System32\OpenWith.exe, C:\Windows\System32\wksprt.exe, C:\Program Files\Windows Photo Viewer\ImagingDevices.exe, and C:\Program Files\Windows Mail\wab.exe. Dohdoor implements EDR bypass by unhooking ntdll.dll system calls — comparing NtProtectVirtualMemory's first bytes against syscall stub pattern (4C 8B D1 B8 FF 00 00 00) and writing a direct syscall trampoline (B8 BB 00 00 00 C3).

Cisco Talos identified a C2 host with JA3S hash '466556e923186364e82cbdb4cad8df2c' and TLS certificate serial '7FF31977972C224A76155D13B6D685E3' matching default Cobalt Strike server signatures, indicating potential Cobalt Strike Beacon deployment.

Talos assesses with low confidence that UAT-10027 is North Korea-nexus based on: (1) shared XOR-SUB position-dependent decryption with constant 0x26 matching Lazarloader, (2) NTDLL unhooking technique alignment, (3) DoH via Cloudflare pattern, (4) process hollowing into ImagingDevices.exe, (5) DLL sideloading with propsys.dll filename, and (6) use of multiple non-traditional TLDs with varying case patterns — all observed in Lazarus Group tradecraft.

MITRE ATT&CK techniques used in TL-2026-0149

credential-access

T1003 OS Credential Dumping

defense-evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.012 Process Hollowing; T1070.004 File Deletion; T1564.001 Hidden Files and Directories

execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.002 Malicious File

command-and-control

T1071.004 DNS; T1090.004 Domain Fronting; T1105 Ingress Tool Transfer; T1573.002 Asymmetric Cryptography

discovery

T1082 System Information Discovery

initial-access

T1566 Phishing

stealth

T1574.001 DLL

resource-development

T1583.001 Domains; T1583.006 Web Services

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Dohdoor Backdoor

  • Microsoft — Windows
    Vulnerable versions: Windows 10/11, Windows Server 2016-2025 (all 64-bit — Dohdoor is 64-bit DLL)
  • Various — US Education Sector Systems
    Vulnerable versions: Active campaign targeting
  • Various — US Healthcare Sector Systems
    Vulnerable versions: Active campaign targeting

Remediation for Dohdoor Backdoor

Immediate actions

  • Block known C2 domains at DNS/proxy: MswInSofTUpDloAd.deSigN, DEEPinSPeCTioNsyStEM.oNLiNe, PNUIsckmHwAgzVdYJRlbeFT.SoftWarE and all variants
  • Hunt for DoH traffic to Cloudflare DNS (1.1.1.1/dns-query) with User-Agent 'insomnia/11.3.0' — unique Dohdoor fingerprint
  • Scan for propsys.dll and batmeter.dll in C:\ProgramData and C:\Users\Public hidden folders
  • Check for Fondue.exe, mblctr.exe, ScreenClippingHost.exe running from non-standard paths (outside System32)
  • Hunt for process hollowing: OpenWith.exe, wksprt.exe, ImagingDevices.exe, wab.exe spawned in suspended state
  • Deploy ClamAV signatures: Win.Loader.Dohdoor-10059347-0, Win.Loader.Dohdoor-10059535-0

Workarounds

  • Block DNS-over-HTTPS at network perimeter if not operationally required
  • Restrict execution of LOLBins from non-standard directories via AppLocker/WDAC
  • Monitor and alert on RunMRU registry key deletion (anti-forensic indicator)

Longer-term hardening

  • Implement DNS-over-HTTPS monitoring: inspect DoH traffic for non-browser User-Agents making DNS queries
  • Deploy EDR with NTDLL unhooking detection — alert on NtProtectVirtualMemory modifications
  • Monitor for DLL sideloading: legitimate LOLBins loading unsigned DLLs from writable directories
  • Implement network segmentation for education and healthcare environments targeted by this campaign
  • Deploy Snort rules: SIDs 65949-65951 (Snort2), 301407/65949 (Snort3)
  • Monitor for JA3S hash '466556e923186364e82cbdb4cad8df2c' — default Cobalt Strike server fingerprint

Weaknesses (CWE) in Dohdoor Backdoor

CWE-506, CWE-829

Timeline of Dohdoor Backdoor

  • Dohdoor DLL compiled (debug string timestamp from 'C:\Users\diablo\Desktop\SimpleDll\TlsClient.hpp')
  • Cisco Talos assesses campaign active since at least December 2025 based on telemetry
  • UAT-10027 observed targeting US education and healthcare sector organizations via phishing campaigns
  • Multiple C2 domains observed across .online, .design, and .software TLDs with Cloudflare-fronted infrastructure
  • C2 host JA3S hash '466556e923186364e82cbdb4cad8df2c' matches default Cobalt Strike server — payload delivery confirmed
  • Threadlinqs Intelligence publishes TL-2026-0149 with full MITRE mapping, simulations, and detection coverage
  • Cisco Talos publishes Dohdoor campaign analysis with IOCs and DPRK attribution assessment. Source: https://blog.talosintelligence.com/new-dohdoor-malware-campaign/
  • As of 2026-05-29, the Dohdoor/UAT-10027 DoH-over-Cloudflare C2 campaign remains active: Cisco Talos (2026-02-26) and corroborating outlets (Hacker News, The Register, Security Affairs) describe it as ongoing with no takedown, disruption, or successor reported through May 2026. It is a malware/TTP threat with no CVE, so KEV/patch status does not apply, and the resilient Cloudflare-fronted infrastructure remains undisrupted.

Sources cited for Dohdoor Backdoor

Detection coverage for TL-2026-0149

As of 2026-02-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0149 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats