Malware & RansomwareHIGH

Dohdoor Malware Targets Education and Healthcare Sectors!

TACisco Talos IntelligenceFeb 26, 2026
DohdoorUAT-10027Cisco Talosmalwarecybersecurity
🎯

Basically, a new malware called Dohdoor is attacking schools and hospitals.

Quick Summary

A new malware named Dohdoor is targeting schools and hospitals. This poses a serious risk to sensitive data and personal information. Cybersecurity teams are on high alert to combat this threat.

What Happened

A new wave of cyberattacks is hitting crucial sectors like education and healthcare. Cisco Talos has uncovered a malicious campaign? that has been active since December 2025. This campaign is linked to a threat actor? known as UAT-10027, who is using a new backdoor? called Dohdoor to infiltrate systems.

The discovery of this malware is alarming, especially since it targets institutions that are vital for public welfare. Schools and hospitals are often under-resourced when it comes to cybersecurity, making them prime targets for cybercriminals. The backdoor? allows attackers to gain unauthorized access to sensitive information, potentially compromising patient data and student records.

Why Should You Care

This isn't just a tech issue; it affects you directly. If you or your loved ones rely on schools or hospitals, a breach could lead to stolen personal information, medical records, or even financial data. Imagine someone having access to your private health information or your child's school records — it’s a nightmare scenario.

Protecting these institutions is crucial, as they handle sensitive data that can be exploited for identity theft or fraud. If you work in or with these sectors, you need to be aware of the risks and take action to safeguard your information.

What's Being Done

In response to this threat, cybersecurity teams are working tirelessly to mitigate the risks associated with the Dohdoor? malware. Here are some immediate actions that affected organizations should consider:

  • Conduct a thorough security audit to identify vulnerabilities.
  • Update all security software to the latest versions.
  • Educate staff about phishing and other common attack methods.

Experts are closely monitoring the situation to see if UAT-10027 will escalate their attacks or if new variants of Dohdoor? will emerge. Staying informed is key to staying safe.

💡 Tap dotted terms for explanations

🔒 Pro insight: The targeting of education and healthcare sectors indicates a strategic shift in threat actor focus towards critical infrastructure vulnerabilities.

Original article from

Cisco Talos Intelligence · Alex Karkins

Read Full Article

Related Pings

HIGHMalware & Ransomware

ClickFix Attackers Evolve Tactics to Bypass Security Measures

Microsoft warns about a new ClickFix phishing tactic. Attackers are tricking users into executing harmful commands via Windows Terminal. This method can compromise your data and security. Stay alert and educate yourself on these evolving threats!

CSO Online·Yesterday, 9:15 PM
HIGHMalware & Ransomware

Fake Google Meet Update Gives Attackers Control of Your PC

A fake Google Meet update is tricking users into giving hackers control of their PCs. This poses a serious risk to personal and sensitive data. Stay vigilant and avoid suspicious update prompts to protect yourself.

Malwarebytes Labs·Yesterday, 7:35 PM
HIGHMalware & Ransomware

Spyware Masquerades as Emergency App Targeting Israeli Smartphones

Israeli smartphones were targeted by spyware disguised as an emergency app. This deceptive tactic puts personal data at risk. Stay vigilant and verify app legitimacy to protect your privacy.

The Register Security·Yesterday, 6:56 PM
HIGHMalware & Ransomware

Metasploit Update: New Exploits and Enhanced Control Features

Metasploit has launched a new update with powerful exploits and features. Users of Tactical RMM and MajorDoMo are particularly at risk. Stay ahead of potential attacks by updating your systems and reviewing security measures.

Rapid7 Blog·Yesterday, 6:28 PM
HIGHMalware & Ransomware

New ClickFix Attack Uses Windows Terminal for Malicious Payloads

A new wave of ClickFix attacks targets Windows Terminal to deliver malicious payloads. Users are at risk of unauthorized access and data theft. Stay cautious and keep your software updated to protect yourself.

Cyber Security News·Yesterday, 6:05 PM
HIGHMalware & Ransomware

AI-Powered Malware: Transparent Tribe Targets India

A hacking group is using AI to create malware targeting India. This mass production of implants could compromise personal data and financial security. Experts recommend updating software and using strong passwords to protect against these threats.

The Hacker News·Yesterday, 3:11 PM