Suspected Nork intruders infecting US healthcare, education
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Cisco Talos researchers have identified an ongoing cyberattack campaign targeting US healthcare and education organizations, attributed with low confidence to a North Korean-linked group called UAT-10027. The attackers use phishing for initial access, then deploy a multi-stage infection chain involving PowerShell, DLL sideloading, and a newly discovered backdoor called Dohdoor. The malware uses DNS-over-HTTPS via Cloudflare to disguise C2 traffic, process hollowing to evade detection, and NTDLL unhooking to bypass EDR tools, ultimately delivering a Cobalt Strike Beacon. Technical overlaps with Lazarus Group's Lazarloader malware suggest a possible connection to North Korea's state-sponsored hacking apparatus.