IC Technology — 2026-07-04

Chinese-Linked ToddyCat APT Deploys Umbrij Tool to Steal Government Cloud Email Tokens Via OAuth Hijacking

BLUFUmbrij's session-hijacking approach renders credential-focused defenses irrelevant and is simple enough for any post-exploitation actor to replicate against cloud email at scale.

Kaspersky's Securelist reported that ToddyCat, tracked since prior campaigns targeting corporate email, developed a tool called Umbrij to compromise Gmail accounts via the Google API rather than by stealing credentials directly 1. Kaspersky said the tool connects to a victim's browser in headless mode through a remote debugging port, then submits a series of requests that yield an OAuth authorization code, which the attackers exchange for an access token to reach Gmail resources under the user's existing session; Kaspersky labeled the technique Shadow Token via Remote Debug 1. Umbrij, a ConfuserEx-obfuscated .NET DLL, is deployed via DLL sideloading alongside signed executables including a Bitdefender ConnectAgent component, a Visual Studio testing tool, and the discontinued GoogleDesktop.exe; Kaspersky identified three variants targeting Chrome and Edge that disguise their OAuth requests using client IDs belonging to legitimate Google Workspace Migration/Sync for Outlook tools, requiring only that the targeted user remain logged into Gmail 12. Kaspersky discovered the tool during a threat hunting operation after spotting a scheduled task impersonating its own endpoint security software, and The Hacker News and GBHackers both relayed the findings without independent details 123.

Analysis
Umbrij marks ToddyCat's shift from credential theft to API-level session hijacking that leaves no signature for credential-focused monitoring to catch, and because it rides ordinary DLL sideloading rather than actor-specific tooling, the technique is straightforward for other espionage actors with post-exploitation access to replicate. Kaspersky's reverse engineering is the only primary technical account; outlets relaying the findings add no independent corroboration. The tool's dependence on already-compromised hosts and duplicated tokens suggests a post-exploitation collection capability rather than a new initial-access vector: existing hardening against ToddyCat's earlier intrusion methods may already limit its reach. Kaspersky's disclosed artifacts, scheduled task names, hashes, and command-line parameters give enterprise defenders concrete hunting signatures for remote-debugging-port abuse and signed-executable sideloading, a detection axis distinct from the credential-theft focus this technique specifically evades.
4 sources
  1. How the ToddyCat APT group gains access to Gmail accounts - Securelist (Kaspersky)
  2. ToddyCat Uses Shadow Token via Remote Debug to Compromise Gmail Accounts - GBHackers
  3. ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API - The Hacker News
  4. ToddyCat APT Umbrij Tool Steals Cloud Email Tokens - Security Online

View in full brief →

UNCLASSIFIED // OPEN SOURCE