Cisco Talos discovered an ongoing malicious campaign since at least as early as December 2025 by a threat actor we track as “UAT-10027,” delivering a previously undisclosed backdoor dubbed “Dohdoor.”
First seen on blog.talosintelligence.com
Jump to article: blog.talosintelligence.com/new-dohdoor-malware-campaign/
![]()

