Malware & RansomwareHIGH

Dohdoor Malware Targets Education and Healthcare Sectors!

TACisco Talos Intelligence
DohdoorUAT-10027Cisco Talosmalwarecybersecurity
🎯

Basically, a new malware called Dohdoor is attacking schools and hospitals.

Quick Summary

A new malware named Dohdoor is targeting schools and hospitals. This poses a serious risk to sensitive data and personal information. Cybersecurity teams are on high alert to combat this threat.

What Happened

A new wave of cyberattacks is hitting crucial sectors like education and healthcare. Cisco Talos has uncovered a malicious campaign? that has been active since December 2025. This campaign is linked to a threat actor? known as UAT-10027, who is using a new backdoor? called Dohdoor to infiltrate systems.

The discovery of this malware is alarming, especially since it targets institutions that are vital for public welfare. Schools and hospitals are often under-resourced when it comes to cybersecurity, making them prime targets for cybercriminals. The backdoor? allows attackers to gain unauthorized access to sensitive information, potentially compromising patient data and student records.

Why Should You Care

This isn't just a tech issue; it affects you directly. If you or your loved ones rely on schools or hospitals, a breach could lead to stolen personal information, medical records, or even financial data. Imagine someone having access to your private health information or your child's school records — it’s a nightmare scenario.

Protecting these institutions is crucial, as they handle sensitive data that can be exploited for identity theft or fraud. If you work in or with these sectors, you need to be aware of the risks and take action to safeguard your information.

What's Being Done

In response to this threat, cybersecurity teams are working tirelessly to mitigate the risks associated with the Dohdoor? malware. Here are some immediate actions that affected organizations should consider:

  • Conduct a thorough security audit to identify vulnerabilities.
  • Update all security software to the latest versions.
  • Educate staff about phishing and other common attack methods.

Experts are closely monitoring the situation to see if UAT-10027 will escalate their attacks or if new variants of Dohdoor? will emerge. Staying informed is key to staying safe.

💡 Tap dotted terms for explanations

🔒 Pro insight: The targeting of education and healthcare sectors indicates a strategic shift in threat actor focus towards critical infrastructure vulnerabilities.

Original article from

Cisco Talos Intelligence · Alex Karkins

Read Full Article

Related Pings

HIGHMalware & Ransomware

AppsFlyer SDK Hijacked to Deploy Crypto-Stealing Malware

What Happened This week, the AppsFlyer Web SDK was hijacked in a serious supply-chain attack. Malicious code was injected into the SDK, which is widely used for marketing analytics by over 15,000 businesses globally. The compromised code was designed to intercept cryptocurrency wallet addresses entered by users on various websites. Instead of sending funds to the intended wallet, the

BleepingComputer·
HIGHMalware & Ransomware

GlassWorm Campaign Exploits 72 Extensions to Target Developers

A new GlassWorm campaign exploits 72 malicious extensions targeting developers. This sophisticated attack uses seemingly harmless tools to deliver malware. Developers must stay vigilant to protect their systems from these threats.

The Hacker News·
HIGHMalware & Ransomware

Malicious npm Packages Steal Discord and Crypto Data

A sophisticated supply chain attack has emerged, targeting Discord and cryptocurrency wallets. Users of npm packages are at risk of having their sensitive data stolen. Immediate action is required to secure accounts and data.

Cyber Security News·
HIGHMalware & Ransomware

GlassWorm Malware Expands Reach with 72 Malicious Extensions

The GlassWorm malware campaign has escalated, infecting developer environments through 72 malicious Open VSX extensions. Developers using popular tools are at risk, as attackers employ clever tricks to bypass security measures. Immediate action is necessary to protect sensitive data and maintain secure coding practices.

Cyber Security News·
HIGHMalware & Ransomware

SmartApeSG Campaign Deploys Remcos RAT via ClickFix Page

A new campaign is using a fake ClickFix page to spread Remcos RAT. Individuals and organizations are at risk of remote access and data theft. Stay vigilant and protect your systems from this growing threat.

SANS ISC Full Text·
HIGHMalware & Ransomware

Ransomware Negotiator Allegedly Extorted Victims for Millions

A ransomware negotiator is accused of extorting victims for millions. DigitalMint claims ignorance of his actions. This scandal raises serious concerns about trust in cybersecurity professionals.

SC Media·