TL;DR

['UAT-10027 is an ongoing cyber espionage campaign that deploys Dohdoor backdoor to U.S. education and healthcare networks via DNS-over-HTTPS (DoH).']

What happened

['Cisco Talos identified a new threat activity cluster, tracked as UAT-10027, targeting US educational institutions and healthcare providers since December 2025.']

Why it matters for ops

['The use of DoH in Dohdoor backdoor complicates detection and response efforts for network security teams.']

Mitigation

  • Implement strict DoH policies in DNS resolvers
  • Monitor network traffic for anomalies and unexpected encrypted communications

Action items

  • Review DNS resolution logs for suspicious activities
  • Update security configurations to mitigate DoH-based threats

Detection IOCs

  • Unusual DNS queries via HTTPS
  • Unexpected encrypted traffic patterns on port 443

Source link

https://thehackernews.com/2026/02/uat-10027-targets-us-education-and.html