---
title: "Suspected Nork intruders infecting US healthcare, education"
url: https://daily.dev/posts/suspected-nork-intruders-infecting-us-healthcare-education-zlelpn1k3
source_url: https://go.theregister.com/feed/www.theregister.com/2026/02/27/suspected_nork_digital_intruders_caught/
type: article
source: "The Register"
published: 2026-02-27T20:04:54.988Z
updated: 2026-02-27T20:05:17.260Z
tags: ["cyber", "malware", "healthcare"]
reading_time: 4
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Suspected Nork intruders infecting US healthcare, education

**[The Register](https://daily.dev/sources/theregister)** · 4 min read · 0 upvotes · 0 comments

## Summary

Cisco Talos researchers have identified an ongoing cyberattack campaign targeting US healthcare and education organizations, attributed with low confidence to a North Korean-linked group called UAT-10027. The attackers use phishing for initial access, then deploy a multi-stage infection chain involving PowerShell, DLL sideloading, and a newly discovered backdoor called Dohdoor. The malware uses DNS-over-HTTPS via Cloudflare to disguise C2 traffic, process hollowing to evade detection, and NTDLL unhooking to bypass EDR tools, ultimately delivering a Cobalt Strike Beacon. Technical overlaps with Lazarus Group's Lazarloader malware suggest a possible connection to North Korea's state-sponsored hacking apparatus.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://go.theregister.com/feed/www.theregister.com/2026/02/27/suspected_nork_digital_intruders_caught/>

## Similar posts on daily.dev

- [North Korea-Linked Hackers Use GitHub as C2 Infrastructure to Attack South Korea](https://daily.dev/posts/north-korea-linked-hackers-use-github-as-c2-infrastructure-to-attack-south-korea-kn4afxqnc) · InfoSec Write-ups · 0 upvotes · 0 comments
- [Lazarus Group targets healthcare orgs with Medusa ransomware](https://daily.dev/posts/lazarus-group-targets-healthcare-orgs-with-medusa-ransomware-uxilrpq3y) · The Register · 0 upvotes · 0 comments
- [Chinese Cyber Threat Lurks In Critical Asian Sectors for Years](https://daily.dev/posts/chinese-cyber-threat-lurks-in-critical-asian-sectors-for-years-8fwvgxfsv) · Dark Reading · 0 upvotes · 0 comments
- [New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea](https://daily.dev/posts/new-httptroy-backdoor-poses-as-vpn-invoice-in-targeted-cyberattack-on-south-korea-dqr6wzczi) · The Hacker News · 0 upvotes · 0 comments
- [Lazarus RAT code resurfaces in North Korean IT-worker scams](https://daily.dev/posts/lazarus-rat-code-resurfaces-in-north-korean-it-worker-scams-emlb2cwiq) · The Register · 1 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#malware](https://daily.dev/tags/malware), [#healthcare](https://daily.dev/tags/healthcare)

[View this post on daily.dev](https://daily.dev/posts/suspected-nork-intruders-infecting-us-healthcare-education-zlelpn1k3)
