Threats
New Threat Actor UAT-10027 Deploys Dohdoor Backdoor Against US Education and Healthcare Using DNS-over-HTTPS for Stealth C2
Cisco Talos has disclosed a previously undocumented threat activity cluster tracked as UAT-10027 that has been targeting US education and healthcare organizations since at least December 2025 with a novel backdoor called Dohdoor. The backdoor uses DNS-over-HTTPS (DoH) for command-and-control communications and hides behind Cloudflare infrastructure, making all outbound C2