Chinese-Linked ToddyCat APT Deploys Umbrij Tool to Steal Government Cloud Email Tokens Via OAuth Hijacking
Kaspersky's Securelist reported that
Umbrij marks ToddyCat's shift from credential theft to API-level session hijacking that leaves no signature for credential-focused monitoring to catch, and because it rides ordinary DLL sideloading rather than actor-specific tooling, the technique is straightforward for other espionage actors with post-exploitation access to replicate. Kaspersky's reverse engineering is the only primary technical account; outlets relaying the findings add no independent corroboration. The tool's dependence on already-compromised hosts and duplicated tokens suggests a post-exploitation collection capability rather than a new initial-access vector: existing hardening against ToddyCat's earlier intrusion methods may already limit its reach. Kaspersky's disclosed artifacts, scheduled task names, hashes, and command-line parameters give enterprise defenders concrete hunting signatures for remote-debugging-port abuse and signed-executable sideloading, a detection axis distinct from the credential-theft focus this technique specifically evades.
4 sources
- How the ToddyCat APT group gains access to Gmail accounts -
Securelist (Kaspersky) - ToddyCat Uses Shadow Token via Remote Debug to Compromise Gmail Accounts -
GBHackers - ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API -
The Hacker News - ToddyCat APT Umbrij Tool Steals Cloud Email Tokens -
Security Online