# Dohdoor Backdoor — UAT-10027 DNS-over-HTTPS C2 Campaign Targeting US Education & Healthcare via Cloudflare Tunnel, DLL Sideloading, Cobalt Strike

> Cisco Talos discovered UAT-10027 deploying a previously undisclosed backdoor called Dohdoor that uses DNS-over-HTTPS (DoH) via Cloudflare for C2 resolution and establishes HTTPS tunnels through Cloudflare edge infrastructure. The multi-stage attack chain targets US education and healthcare sectors through phishing, PowerShell downloaders, batch script droppers, and DLL sideloading of LOLBins (Fondue.exe, mblctr.exe, ScreenClippingHost.exe). Dohdoor reflectively loads Cobalt Strike Beacon into legitimate Windows processes via process hollowing. Low-confidence North Korea/Lazarus attribution based on shared XOR-SUB decryption constant (0x26) and NTDLL unhooking techniques.

- **Published:** 2026-02-26T22:39:00Z
- **Last reviewed:** 2026-02-26T22:39:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0149
- **ID:** TL-2026-0149
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** UAT-10027 (North Korea)
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Cisco Talos discovered an ongoing campaign by threat actor UAT-10027 active since at least December 2025. The campaign delivers a previously undisclosed backdoor dubbed Dohdoor that targets US education and healthcare sectors.

The multi-stage attack chain begins with social engineering phishing delivering a PowerShell script. The PowerShell executes curl.exe with an encoded URL to download a Windows batch file (.bat/.cmd). The batch script creates a hidden workspace in C:\ProgramData or C:\Users\Public, downloads a malicious DLL from the C2 server (via URL path /111111?sub=d), and disguises it as a legitimate Windows DLL — specifically propsys.dll or batmeter.dll. The script then copies legitimate Windows executables (Fondue.exe, mblctr.exe, ScreenClippingHost.exe) into the workspace folder and executes them, passing the C2 URL /111111?sub=s as a command-line argument. These legitimate executables sideload the malicious DLL. The batch script performs anti-forensic cleanup: deleting Run command history from RunMRU registry, clearing clipboard data, and self-deleting.

Dohdoor is a 64-bit DLL compiled November 25, 2025, with debug string 'C:\Users\diablo\Desktop\SimpleDll\TlsClient.hpp'. It dynamically resolves Windows APIs using hash-based lookups (avoiding static IAT detection). For C2 communication, Dohdoor employs DNS-over-HTTPS (DoH) via Cloudflare's DNS service — sending encrypted DNS queries over HTTPS port 443 with User-Agent 'insomnia/11.3.0' and Accept 'applications/dns-json'. It parses JSON responses by searching for 'Answer' and 'data' string patterns rather than using a full JSON parser.

The C2 infrastructure uses subdomain names mimicking Microsoft Windows software updates ('MswInSofTUpDloAd') and security appliances ('DEEPinSPeCTioNsyStEM'), with irregular capitalization across non-traditional TLDs (.OnLiNe, .DeSigN, .SoFTWARe). This capitalization strategy bypasses string-matching filters and provides infrastructure redundancy.

Dohdoor receives encrypted payloads using custom XOR-SUB decryption with a position-dependent cipher. The encrypted data has a 4:1 expansion ratio. Decryption uses SIMD vectorized processing for 16-byte blocks and a fallback formula: decrypted[i] = encrypted[i*4] - i - 0x26. The constant 0x26 is shared with Lazarus Group's Lazarloader tool.

Decrypted payloads are injected into legitimate Windows processes via process hollowing. Hardcoded targets: C:\Windows\System32\OpenWith.exe, C:\Windows\System32\wksprt.exe, C:\Program Files\Windows Photo Viewer\ImagingDevices.exe, and C:\Program Files\Windows Mail\wab.exe. Dohdoor implements EDR bypass by unhooking ntdll.dll system calls — comparing NtProtectVirtualMemory's first bytes against syscall stub pattern (4C 8B D1 B8 FF 00 00 00) and writing a direct syscall trampoline (B8 BB 00 00 00 C3).

Cisco Talos identified a C2 host with JA3S hash '466556e923186364e82cbdb4cad8df2c' and TLS certificate serial '7FF31977972C224A76155D13B6D685E3' matching default Cobalt Strike server signatures, indicating potential Cobalt Strike Beacon deployment.

Talos assesses with low confidence that UAT-10027 is North Korea-nexus based on: (1) shared XOR-SUB position-dependent decryption with constant 0x26 matching Lazarloader, (2) NTDLL unhooking technique alignment, (3) DoH via Cloudflare pattern, (4) process hollowing into ImagingDevices.exe, (5) DLL sideloading with propsys.dll filename, and (6) use of multiple non-traditional TLDs with varying case patterns — all observed in Lazarus Group tradecraft.

## MITRE ATT&CK

- T1566 Phishing
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1204.002 Malicious File
- T1574.001 DLL
- T1055.012 Process Hollowing
- T1036.005 Match Legitimate Resource Name or Location
- T1027 Obfuscated Files or Information
- T1070.004 File Deletion
- T1685 Disable or Modify Tools
- T1564.001 Hidden Files and Directories
- T1003 OS Credential Dumping
- T1082 System Information Discovery
- T1071.004 DNS
- T1573.002 Asymmetric Cryptography
- T1090.004 Domain Fronting
- T1105 Ingress Tool Transfer
- T1583.001 Domains
- T1583.006 Web Services

## Sources

- [Cisco Talos — New Dohdoor malware campaign targets education and health care](https://blog.talosintelligence.com/new-dohdoor-malware-campaign/)
- [Cisco Talos IOCs — Dohdoor campaign (GitHub)](https://github.com/Cisco-Talos/IOCs/blob/main/2026/02/new-dohdoor-malware-campaign.txt)
- [S2W Inc — Lazarloader analysis (XOR-SUB decryption overlap)](https://s2w.inc/en/resource/detail/941)
- [AhnLab ASEC — Lazarus Group DLL sideloading propsys.dll tradecraft](https://asec.ahnlab.com/ko/33948/)
- [CISA — North Korean State-Sponsored Actors Use Maui Ransomware (Healthcare targeting)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-187a)
- [Global Cyber Alliance — Kimsuky Education Sector Targeting](https://globalcyberalliance.org/aide-data-kimsuky/)
- [Threadlinqs — TL-2026-0148 Contagious Interview (related: DPRK developer targeting)](https://intel.threadlinqs.com/threat/TL-2026-0148)
- [Threadlinqs — TL-2026-0140 Lazarus Medusa Ransomware (related: DPRK operations)](https://intel.threadlinqs.com/threat/TL-2026-0140)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0149
