ToddyCat is an advanced persistent threat group engaged primarily in cyber-espionage, with activity publicly tracked since at least 2020 and victimology concentrated in organizations across Europe and Asia. The group has been associated with stealth-focused post-compromise tradecraft, long-term persistence, and collection of sensitive enterprise data, including email and document repositories. Aliases include Storm-0247 and Websiic. ToddyCat has demonstrated a strong emphasis on abusing legitimate services and trusted software to evade detection. Reported operations include exploitation of known server-side vulnerabilities for initial access, use of malicious loaders, and repeated reliance on DLL sideloading and proxying to execute payloads through legitimate signed applications. In separate activity, the group used a legitimate media player process to sideload a remote access trojan, and later employed a custom tool known as TCESB to execute payloads from within a security product process while attempting to bypass endpoint protection and monitoring. TCESB has been linked to abuse of a vulnerable driver and kernel-notification tampering, reflecting a mature capability for defense evasion. The group is also notable for cloud- and identity-centric intrusion techniques. ToddyCat developed a technique named Shadow Token via Remote Debug (STRD) to obtain persistent access to Google Workspace resources by abusing OAuth 2.0 delegated authorization from an already compromised endpoint. This technique was implemented with malware known as Umbrij, a .NET tool that enumerates Chromium-based browser profiles, duplicates authenticated profile data, launches a hidden browser instance in remote debugging mode, and automates OAuth consent flows through the DevTools protocol and Puppeteer. By impersonating legitimate Google Workspace synchronization or migration applications and harvesting authorization artifacts, ToddyCat can gain durable API-based access to victim mailboxes and related cloud resources without continued dependence on the compromised host. This tradecraft aligns with broader observations that ToddyCat favors cloud services, OAuth tokens, and legitimate platforms for persistence and collection. Observed host-based behavior attributed to ToddyCat includes PowerShell and command-shell execution, hidden-window script execution, process and security-software discovery, account discovery using domain user enumeration, collection of recently modified office and PDF documents, system and removable-drive information gathering, and manual staging or transfer of collected files. The group has also been linked to theft of Microsoft Outlook email data through a custom tool called TCSectorCopy, further underscoring its focus on communications intelligence. Overall, ToddyCat is characterized by stealthy espionage operations, custom malware development, abuse of trusted binaries and security tooling, and increasing sophistication in cloud account compromise and token-based persistence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
APT41 leveraged vulnerabilities such as ProxyLogon exploitation... APT41 exploited CVE-2021-26855 against a vulnerable Microsoft Exchange Server... Threat Group-3390 ... exploited ... CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in Exchange Server. ToddyCat has exploited the ProxyLogon vulnerability (CVE-2021-26855)...
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065
10 more CVEs tied to this actor tracked in Mallory.
46 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage-focused threat actor using the Shadow Token via Remote Debug (STRD) technique to obtain persistent OAuth 2.0 access to victims’ Google Workspace mailboxes and other resources. The group previously exploited known server-side vulnerabilities and delivered malicious loaders via messengers; in the described attack it used the Umbrij malware to clone browser profiles, launch Chrome/Edge in headless remote-debug mode, automate OAuth consent flows, and steal authorization codes for long-term mailbox access.
Espionage-focused operations using the Shadow Token via Remote Debug (STRD) technique to establish persistent access to victims’ Google Workspace mailboxes via OAuth 2.0 tokens, enabling long-term access that can survive password resets.
Associated with exploiting cloud environments, OAuth tokens, and legitimate services.
Conducting espionage-focused compromises of corporate email communications, including use of the Umbrij malware to hijack Gmail/Google API access via OAuth token theft from active browser sessions, and previously using TCSectorCopy to obtain Microsoft Outlook email data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.