Threat IntelHIGH

UAT-10027 Targets U.S. Education and Healthcare with New Backdoor

THThe Hacker News19h ago2 min read
UAT-10027DohdoorCisco Taloseducationhealthcare
🎯

Basically, a new cyberattack is hitting schools and hospitals in the U.S.

Quick Summary

A new cyber campaign named UAT-10027 is targeting U.S. education and healthcare sectors. This attack uses a backdoor called Dohdoor, putting sensitive data at risk. Immediate action is needed to protect these critical services.

What Happened

A new cyber threat is here, and it’s targeting something we all rely on: education and healthcare. Cisco Talos has identified a malicious campaign? known as UAT-10027 that has been active since December 2025. This campaign is not just any run-of-the-mill attack; it aims to deliver a sophisticated backdoor? called Dohdoor.

Dohdoor is unique because it uses a technology called DNS-over-HTTPS (DoH). This means it can hide its activities by blending in with regular web traffic, making it harder to detect. The attackers are focused on infiltrating systems in schools and hospitals, potentially compromising sensitive data? and operations.

Why Should You Care

You might think this doesn't affect you, but if you or your family rely on schools or healthcare services, it absolutely does. Imagine your child's school being disrupted or your doctor unable to access your medical records. This attack could lead to serious consequences for your education and health systems.

In today’s world, where everything is connected, a breach in these sectors can ripple out, affecting your personal information and safety. Think of it like a chain reaction: when one link breaks, it can impact everyone connected to it.

What's Being Done

Cisco Talos is actively monitoring? this threat and working on ways to mitigate the risks. If you are part of an educational institution or healthcare organization, here are some immediate actions to take:

  • Update your security protocols to defend against potential breaches.
  • Educate staff on recognizing phishing attempts and suspicious activities.
  • Monitor network traffic for unusual patterns that could indicate a breach.

Experts are keeping a close eye on UAT-10027, watching for how it evolves and what new tactics it may employ in the future. Stay alert, because the landscape of cyber threats is constantly changing.

💡 Tap dotted terms for explanations

🔒 Pro insight: The use of DNS-over-HTTPS in Dohdoor signifies a shift towards stealthier, more sophisticated cyberattack methodologies.

Original article from

The Hacker News

Read Full Article

Related Pings

HIGHThreat Intel

Cyber Security Report 2026: Key Insights Unveiled

A new report reveals crucial trends in cybersecurity for 2026. It highlights rising threats like ransomware and phishing that affect everyone. Protecting your digital life is essential as attacks become more sophisticated. Stay updated and vigilant to safeguard your information.

Check Point Research·Just now·2m
HIGHThreat Intel

DDoS Attacks Surge: Japan's Websites Targeted

Japanese websites are experiencing a surge in DDoS attacks using reflection packets. Major companies, including banks and airlines, are being targeted. This matters because such attacks can cripple online services, affecting your access to essential sites. JPCERT/CC is monitoring the situation and sharing data to help mitigate risks.

JPCERT/CC·Just now·2m
HIGHThreat Intel

Spyware Campaign Exploits Wartime Panic in Israel

A new spyware campaign is exploiting the Israel-Iran conflict by sending a fake Red Alert app via SMS. This poses serious risks to personal safety and privacy. Stay vigilant and only download apps from trusted sources.

Infosecurity Magazine·Just now·2m
HIGHThreat Intel

Alert Fatigue: Modern SOCs Combat Overwhelming Noise

Security teams are facing overwhelming alert fatigue, making it hard to respond effectively. This affects everyone from analysts to organizations at large. Discover how modern SOCs are tackling this issue with new strategies and tools to streamline investigations and enhance security.

Rapid7 Blog·Just now·2m
HIGHThreat Intel

HoneyMyte Unleashes New Stealers in CoolClient Update

Kaspersky reveals that HoneyMyte has updated its CoolClient backdoor, deploying new data-stealing tools. This poses a risk to your online security. Stay informed and protect your sensitive information!

Kaspersky Securelist·Just now·3m
HIGHThreat Intel

PurpleBravo Exploits Job Offers to Target Software Supply Chains

PurpleBravo, a North Korean cyber group, is using fake job offers to target software supply chains. This tactic threatens the security of applications and services we rely on daily. Stay informed and protect your data from potential breaches.

Recorded Future Blog·Just now·2m