Threat IntelHIGH

UAT-10027 Targets U.S. Education and Healthcare with New Backdoor

THThe Hacker NewsFeb 26, 2026
UAT-10027DohdoorCisco Taloseducationhealthcare
🎯

Basically, a new cyberattack is hitting schools and hospitals in the U.S.

Quick Summary

A new cyber campaign named UAT-10027 is targeting U.S. education and healthcare sectors. This attack uses a backdoor called Dohdoor, putting sensitive data at risk. Immediate action is needed to protect these critical services.

What Happened

A new cyber threat is here, and it’s targeting something we all rely on: education and healthcare. Cisco Talos has identified a malicious campaign? known as UAT-10027 that has been active since December 2025. This campaign is not just any run-of-the-mill attack; it aims to deliver a sophisticated backdoor? called Dohdoor.

Dohdoor is unique because it uses a technology called DNS-over-HTTPS (DoH). This means it can hide its activities by blending in with regular web traffic, making it harder to detect. The attackers are focused on infiltrating systems in schools and hospitals, potentially compromising sensitive data? and operations.

Why Should You Care

You might think this doesn't affect you, but if you or your family rely on schools or healthcare services, it absolutely does. Imagine your child's school being disrupted or your doctor unable to access your medical records. This attack could lead to serious consequences for your education and health systems.

In today’s world, where everything is connected, a breach in these sectors can ripple out, affecting your personal information and safety. Think of it like a chain reaction: when one link breaks, it can impact everyone connected to it.

What's Being Done

Cisco Talos is actively monitoring? this threat and working on ways to mitigate the risks. If you are part of an educational institution or healthcare organization, here are some immediate actions to take:

  • Update your security protocols to defend against potential breaches.
  • Educate staff on recognizing phishing attempts and suspicious activities.
  • Monitor network traffic for unusual patterns that could indicate a breach.

Experts are keeping a close eye on UAT-10027, watching for how it evolves and what new tactics it may employ in the future. Stay alert, because the landscape of cyber threats is constantly changing.

💡 Tap dotted terms for explanations

🔒 Pro insight: The use of DNS-over-HTTPS in Dohdoor signifies a shift towards stealthier, more sophisticated cyberattack methodologies.

Original article from

The Hacker News

Read Full Article

Related Pings

HIGHThreat Intel

Alignment: The Key to Cybersecurity Success

Organizations are prioritizing alignment in cybersecurity to enhance their defenses. This affects everyone, as misalignment can leave your data exposed. Companies are now investing in training and collaboration to strengthen their security posture. Stay informed about how these changes impact your safety online.

Anthropic Research·Today, 3:38 AM
HIGHThreat Intel

FBI Probes Suspicious Cyber Activity on Surveillance Systems

The FBI is looking into suspicious cyber activity affecting sensitive surveillance systems. This could impact privacy and data security. Stay informed and review your own security practices.

SecurityWeek·Today, 1:01 AM
MEDIUMThreat Intel

AI-Powered Cyber Defense: Trump's New Strategy Unveiled

The Trump administration has announced a new cybersecurity strategy focusing on AI for defense. While promising, it lacks crucial details. This could affect your online security, so stay informed about developments.

Cybersecurity Dive·Yesterday, 10:36 PM
HIGHThreat Intel

Iran's MuddyWater Breaches Multiple U.S. Organizations

Iran's MuddyWater hacking group has breached multiple U.S. organizations, raising significant security alarms. These attacks could compromise sensitive information and disrupt essential services. The FBI is investigating, and Cisco has issued critical patches to address vulnerabilities.

CyberWire Daily·Yesterday, 9:30 PM
HIGHThreat Intel

MuddyWater APT Hits U.S. Organizations with Dindoor Malware

MuddyWater, an Iranian hacker group, is targeting U.S. organizations with new Dindoor malware. Banks, airports, and nonprofits are at risk of data breaches and disruptions. Cybersecurity teams are responding with updates and monitoring measures to protect sensitive information.

Security Affairs·Yesterday, 8:05 PM
HIGHThreat Intel

North Korean Threat Groups Exploit AI for Fake Worker Schemes

North Korean hackers are using AI to create fake job applicants. This tactic poses serious risks to companies and their sensitive data. Microsoft warns organizations to enhance their recruitment processes to combat this growing threat.

CyberScoop·Yesterday, 7:16 PM