Threat reportMalwareTL-2026-0149
Dohdoor Backdoor — UAT-10027 DNS-over-HTTPS C2 Campaign Targeting US Education & Healthcare via Cloudflare Tunnel, DLL Sideloading, Cobalt Strike
Dohdoor Backdoor (TL-2026-0149), also tracked as Dohdoor, is a high-severity malware campaign, first published 2026-02-26. It is attributed to UAT-10027 (North Korea) with low confidence, affects Microsoft Windows, maps to 19 MITRE ATT&CK techniques (T1003, T1027, T1036.005), and is covered by 9 detection rules and 16 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK
- Actors
- 1UAT-10027
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-0149
- Threat ID
- TL-2026-0149
- Also known as
- Dohdoor
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- UAT-10027
- Attribution confidence
- LOW
- Nation-state nexus
- North Korea
- Motivation
- ESPIONAGE
- Target sectors
- education, healthcare
- Target regions
- United States
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Dohdoor Backdoor
Malware and tooling: Dohdoor, Cobalt Strike
How Dohdoor Backdoor works
Cisco Talos discovered UAT-10027 deploying a previously undisclosed backdoor called Dohdoor that uses DNS-over-HTTPS (DoH) via Cloudflare for C2 resolution and establishes HTTPS tunnels through Cloudflare edge infrastructure. The multi-stage attack chain targets US education and healthcare sectors through phishing, PowerShell downloaders, batch script droppers, and DLL sideloading of LOLBins (Fondue.exe, mblctr.exe, ScreenClippingHost.exe). Dohdoor reflectively loads Cobalt Strike Beacon into legitimate Windows processes via process hollowing. Low-confidence North Korea/Lazarus attribution based on shared XOR-SUB decryption constant (0x26) and NTDLL unhooking techniques.
Cisco Talos discovered an ongoing campaign by threat actor UAT-10027 active since at least December 2025. The campaign delivers a previously undisclosed backdoor dubbed Dohdoor that targets US education and healthcare sectors.
The multi-stage attack chain begins with social engineering phishing delivering a PowerShell script. The PowerShell executes curl.exe with an encoded URL to download a Windows batch file (.bat/.cmd). The batch script creates a hidden workspace in C:\ProgramData or C:\Users\Public, downloads a malicious DLL from the C2 server (via URL path /111111?sub=d), and disguises it as a legitimate Windows DLL — specifically propsys.dll or batmeter.dll. The script then copies legitimate Windows executables (Fondue.exe, mblctr.exe, ScreenClippingHost.exe) into the workspace folder and executes them, passing the C2 URL /111111?sub=s as a command-line argument. These legitimate executables sideload the malicious DLL. The batch script performs anti-forensic cleanup: deleting Run command history from RunMRU registry, clearing clipboard data, and self-deleting.
Dohdoor is a 64-bit DLL compiled November 25, 2025, with debug string 'C:\Users\diablo\Desktop\SimpleDll\TlsClient.hpp'. It dynamically resolves Windows APIs using hash-based lookups (avoiding static IAT detection). For C2 communication, Dohdoor employs DNS-over-HTTPS (DoH) via Cloudflare's DNS service — sending encrypted DNS queries over HTTPS port 443 with User-Agent 'insomnia/11.3.0' and Accept 'applications/dns-json'. It parses JSON responses by searching for 'Answer' and 'data' string patterns rather than using a full JSON parser.
The C2 infrastructure uses subdomain names mimicking Microsoft Windows software updates ('MswInSofTUpDloAd') and security appliances ('DEEPinSPeCTioNsyStEM'), with irregular capitalization across non-traditional TLDs (.OnLiNe, .DeSigN, .SoFTWARe). This capitalization strategy bypasses string-matching filters and provides infrastructure redundancy.
Dohdoor receives encrypted payloads using custom XOR-SUB decryption with a position-dependent cipher. The encrypted data has a 4:1 expansion ratio. Decryption uses SIMD vectorized processing for 16-byte blocks and a fallback formula: decrypted[i] = encrypted[i*4] - i - 0x26. The constant 0x26 is shared with Lazarus Group's Lazarloader tool.
Decrypted payloads are injected into legitimate Windows processes via process hollowing. Hardcoded targets: C:\Windows\System32\OpenWith.exe, C:\Windows\System32\wksprt.exe, C:\Program Files\Windows Photo Viewer\ImagingDevices.exe, and C:\Program Files\Windows Mail\wab.exe. Dohdoor implements EDR bypass by unhooking ntdll.dll system calls — comparing NtProtectVirtualMemory's first bytes against syscall stub pattern (4C 8B D1 B8 FF 00 00 00) and writing a direct syscall trampoline (B8 BB 00 00 00 C3).
Cisco Talos identified a C2 host with JA3S hash '466556e923186364e82cbdb4cad8df2c' and TLS certificate serial '7FF31977972C224A76155D13B6D685E3' matching default Cobalt Strike server signatures, indicating potential Cobalt Strike Beacon deployment.
Talos assesses with low confidence that UAT-10027 is North Korea-nexus based on: (1) shared XOR-SUB position-dependent decryption with constant 0x26 matching Lazarloader, (2) NTDLL unhooking technique alignment, (3) DoH via Cloudflare pattern, (4) process hollowing into ImagingDevices.exe, (5) DLL sideloading with propsys.dll filename, and (6) use of multiple non-traditional TLDs with varying case patterns — all observed in Lazarus Group tradecraft.
MITRE ATT&CK techniques used in TL-2026-0149
credential-access
defense-evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.012 Process Hollowing; T1070.004 File Deletion; T1564.001 Hidden Files and Directories
execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.002 Malicious File
command-and-control
T1071.004 DNS; T1090.004 Domain Fronting; T1105 Ingress Tool Transfer; T1573.002 Asymmetric Cryptography
discovery
T1082 System Information Discovery
initial-access
stealth
resource-development
T1583.001 Domains; T1583.006 Web Services
defense-impairment
Affected products and versions in Dohdoor Backdoor
- Microsoft — Windows
Vulnerable versions: Windows 10/11, Windows Server 2016-2025 (all 64-bit — Dohdoor is 64-bit DLL) - Various — US Education Sector Systems
Vulnerable versions: Active campaign targeting - Various — US Healthcare Sector Systems
Vulnerable versions: Active campaign targeting
Remediation for Dohdoor Backdoor
Immediate actions
- Block known C2 domains at DNS/proxy: MswInSofTUpDloAd.deSigN, DEEPinSPeCTioNsyStEM.oNLiNe, PNUIsckmHwAgzVdYJRlbeFT.SoftWarE and all variants
- Hunt for DoH traffic to Cloudflare DNS (1.1.1.1/dns-query) with User-Agent 'insomnia/11.3.0' — unique Dohdoor fingerprint
- Scan for propsys.dll and batmeter.dll in C:\ProgramData and C:\Users\Public hidden folders
- Check for Fondue.exe, mblctr.exe, ScreenClippingHost.exe running from non-standard paths (outside System32)
- Hunt for process hollowing: OpenWith.exe, wksprt.exe, ImagingDevices.exe, wab.exe spawned in suspended state
- Deploy ClamAV signatures: Win.Loader.Dohdoor-10059347-0, Win.Loader.Dohdoor-10059535-0
Workarounds
- Block DNS-over-HTTPS at network perimeter if not operationally required
- Restrict execution of LOLBins from non-standard directories via AppLocker/WDAC
- Monitor and alert on RunMRU registry key deletion (anti-forensic indicator)
Longer-term hardening
- Implement DNS-over-HTTPS monitoring: inspect DoH traffic for non-browser User-Agents making DNS queries
- Deploy EDR with NTDLL unhooking detection — alert on NtProtectVirtualMemory modifications
- Monitor for DLL sideloading: legitimate LOLBins loading unsigned DLLs from writable directories
- Implement network segmentation for education and healthcare environments targeted by this campaign
- Deploy Snort rules: SIDs 65949-65951 (Snort2), 301407/65949 (Snort3)
- Monitor for JA3S hash '466556e923186364e82cbdb4cad8df2c' — default Cobalt Strike server fingerprint
Weaknesses (CWE) in Dohdoor Backdoor
Timeline of Dohdoor Backdoor
- Dohdoor DLL compiled (debug string timestamp from 'C:\Users\diablo\Desktop\SimpleDll\TlsClient.hpp')
- Cisco Talos assesses campaign active since at least December 2025 based on telemetry
- UAT-10027 observed targeting US education and healthcare sector organizations via phishing campaigns
- Multiple C2 domains observed across .online, .design, and .software TLDs with Cloudflare-fronted infrastructure
- C2 host JA3S hash '466556e923186364e82cbdb4cad8df2c' matches default Cobalt Strike server — payload delivery confirmed
- Threadlinqs Intelligence publishes TL-2026-0149 with full MITRE mapping, simulations, and detection coverage
- Cisco Talos publishes Dohdoor campaign analysis with IOCs and DPRK attribution assessment. Source: https://blog.talosintelligence.com/new-dohdoor-malware-campaign/
- As of 2026-05-29, the Dohdoor/UAT-10027 DoH-over-Cloudflare C2 campaign remains active: Cisco Talos (2026-02-26) and corroborating outlets (Hacker News, The Register, Security Affairs) describe it as ongoing with no takedown, disruption, or successor reported through May 2026. It is a malware/TTP threat with no CVE, so KEV/patch status does not apply, and the resilient Cloudflare-fronted infrastructure remains undisrupted.
Sources cited for Dohdoor Backdoor
- Cisco Talos — New Dohdoor malware campaign targets education and health care
- Cisco Talos IOCs — Dohdoor campaign (GitHub)
- S2W Inc — Lazarloader analysis (XOR-SUB decryption overlap)
- AhnLab ASEC — Lazarus Group DLL sideloading propsys.dll tradecraft
- CISA — North Korean State-Sponsored Actors Use Maui Ransomware (Healthcare targeting)
- Global Cyber Alliance — Kimsuky Education Sector Targeting
- Threadlinqs — TL-2026-0148 Contagious Interview (related: DPRK developer targeting)
- Threadlinqs — TL-2026-0140 Lazarus Medusa Ransomware (related: DPRK operations)
Detection coverage for TL-2026-0149
As of 2026-02-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0149 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.