Skip to main content
Mallory
19 malware familiesExploits CVEs in the wild

ToddyCat

Also known asStorm-0247ToddyCatWebsiic

ToddyCat is a threat actor also referred to in the provided content as Storm-0247 and Websiic. The content links Websiic to targeting unpatched Microsoft Exchange servers via ProxyLogon, including seven email servers belonging to private companies in the IT, telecommunications, and engineering sectors in Asia and a governmental body in Eastern Europe. Observed ToddyCat tradecraft in the provided content includes exploitation of public-facing applications, use of web shells and IIS components for persistence, execution via Windows command shell, batch scripts, PowerShell, and WMI, and use of scheduled tasks to run discovery commands and collection scripts. The actor has been observed running cmd /c start /b tasklist to enumerate processes, using ping %REMOTE_HOST% for post-exploitation discovery, collecting documents from targeted hosts with scripts, and manually transferring collected files to an exfiltration host with xcopy. The content also states that ToddyCat used a Dropbox uploader to exfiltrate stolen files and used the name debug.exe for malware components.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

14 of 15 tactics73 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1595
Active Scanning
TA0042
Resource Development
1 technique
T1608×2
Stage Capabilities
T1608.001
Upload Malware
T1608.002
Upload Tool
TA0001
Initial Access
3 techniques
T1078
Valid Accounts
T1078.002
Domain Accounts
T1133×4
External Remote Services
T1190×17
Exploit Public-Facing Application
TA0002
Execution
7 techniques
T1047
Windows Management Instrumentation
T1053
Scheduled Task/Job
T1053.005×5
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001×11
PowerShell
T1059.003×3
Windows Command Shell
T1106
Native API
T1129
Shared Modules
T1204
User Execution
T1204.002×2
Malicious File
T1574
Hijack Execution Flow
TA0003
Persistence
4 techniques
T1053
Scheduled Task/Job
T1053.005×5
Scheduled Task
T1078
Valid Accounts
T1078.002
Domain Accounts
T1133×4
External Remote Services
T1505
Server Software Component
T1505.003
Web Shell
T1505.004
IIS Components
TA0004
Privilege Escalation
4 techniques
T1053
Scheduled Task/Job
T1053.005×5
Scheduled Task
T1055
Process Injection
T1078
Valid Accounts
T1078.002
Domain Accounts
T1484
Domain or Tenant Policy Modification
T1484.001
Group Policy Modification
TA0005
Stealth
6 techniques
T1027
Obfuscated Files or Information
T1027.005
Indicator Removal from Tools
T1036
Masquerading
T1055
Process Injection
T1078
Valid Accounts
T1078.002
Domain Accounts
T1564
Hide Artifacts
T1564.003×2
Hidden Window
T1574
Hijack Execution Flow
TA0112
Defense Impairment
1 technique
T1484
Domain or Tenant Policy Modification
T1484.001
Group Policy Modification
TA0006
Credential Access
2 techniques
T1187
Forced Authentication
T1557
Adversary-in-the-Middle
T1557.001
Name Resolution Poisoning and SMB Relay
TA0007
Discovery
11 techniques
T1012
Query Registry
T1018×2
Remote System Discovery
T1046
Network Service Discovery
T1049
System Network Connections Discovery
T1057
Process Discovery
T1069
Permission Groups Discovery
T1069.001
Local Groups
T1069.002×4
Domain Groups
T1082
System Information Discovery
T1083×2
File and Directory Discovery
T1087
Account Discovery
T1087.002×3
Domain Account
T1482
Domain Trust Discovery
T1518
Software Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.002×2
SMB/Windows Admin Shares
TA0009
Collection
3 techniques
T1005×2
Data from Local System
T1557
Adversary-in-the-Middle
T1557.001
Name Resolution Poisoning and SMB Relay
T1560
Archive Collected Data
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1105
Ingress Tool Transfer
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
T1567.002×5
Exfiltration to Cloud Storage
ARSENAL

Associated malware families

19 malware families attributed to this actor across reporting.

14 additional families tracked in Mallory.

WEAPONIZED

Associated vulnerabilities

12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.

CVE-2021-26855ProxyLogon SSRF in Microsoft Exchange ServerIn the wildEvidence4

APT41 leveraged vulnerabilities such as ProxyLogon exploitation... APT41 exploited CVE-2021-26855 against a vulnerable Microsoft Exchange Server... Threat Group-3390 ... exploited ... CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in Exchange Server. ToddyCat has exploited the ProxyLogon vulnerability (CVE-2021-26855)...

CVE-2025-9491Microsoft Windows LNK File UI Misrepresentation Remote Code Execution VulnerabilityIn the wildEvidence2

This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.

CVE-2021-26857Microsoft Exchange Unified Messaging insecure deserialization RCEIn the wildEvidence1

Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065

CVE-2021-26858Microsoft Exchange Server post-auth arbitrary file write (ProxyLogon)In the wildEvidence1

Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065

CVE-2021-27065ProxyLogon post-auth arbitrary file write in Microsoft Exchange ServerIn the wildEvidence1

Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065

7 more CVEs tied to this actor tracked in Mallory.

IOCS

Observables

36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping48

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal19

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs12

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables36

Domains, IPs, and hashes tied to this actor, refreshed continuously.