TCSectorCopy is a custom C++ utility used by the ToddyCat APT to steal Microsoft Outlook email data from compromised corporate environments. Kaspersky reported its use in late 2024 and 2025 as part of ToddyCat’s shift toward covert collection of business correspondence from organizations in Europe and Asia, including targets using on-premises Exchange and cloud-based Microsoft 365 mail environments. The tool opens the disk as a read-only device and copies Outlook Offline Storage Table (OST) files sector by sector, allowing the attackers to bypass file-lock restrictions that Outlook enforces while the application is running. It has also been referenced under the filename xCopy.exe. After extraction, the stolen OST files are processed with the open-source XstReader tool to parse OST/PST archives and access email contents. High-confidence associations in the content link TCSectorCopy specifically to ToddyCat’s post-exploitation email theft operations; the content does not provide standalone network IOCs for the tool, but notes that Kaspersky published related malicious filenames, paths, and directories as indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In November 2025, Kaspersky detailed the hacking group's use of a custom tool dubbed TCSectorCopy to lay their hands on Microsoft Outlook email data belonging to targeted companies.
1 distinct technique documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TCSectorCopy is a custom ToddyCat tool previously used to steal Microsoft Outlook email data from targeted companies.
Specialized utility used to copy Microsoft Outlook OST files (local cached mailbox data) for email data theft.
C++-Dienstprogramm, das Datenträger im Read-only-Modus öffnet, um Outlook-OST-Dateien zu kopieren und dabei Outlook-Dateisperren zu umgehen, um E-Mail-Daten zur Exfiltration zu erlangen.
C++ utility used to exfiltrate Outlook offline storage (OST) by performing sector-by-sector copying from a read-only disk handle, bypassing file locks to obtain mail archives for later parsing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.