XstReader is an open-source viewer for parsing OST/PST email archives. In the provided reporting, it was leveraged by the ToddyCat APT as part of post-exploitation activity to access the contents of corporate Outlook correspondence after OST files were extracted from compromised environments. Kaspersky-linked reporting states that ToddyCat used a separate tool, TCSectorCopy, to copy Outlook OST files while bypassing file-lock mechanisms, then fed the extracted files into XstReader to analyze and extract electronic correspondence contents. The activity is associated with espionage-focused intrusions against corporate environments using on-premises Exchange or cloud-based mail systems, and is discussed in the broader context of ToddyCat operations targeting high-profile organizations, including government and military networks in Europe and Asia. No standalone infection vector or malware-specific IOCs for XstReader itself are provided in the content beyond its use to process extracted OST/PST archives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Once OST files are extracted, they are fed into XstReader — an open-source viewer capable of parsing OST/PST mail archives — allowing the attackers to access the full content of corporate correspondence.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-Source-Viewer/Parser zur Analyse von Outlook-OST/PST-Archiven; wird hier zur Auswertung exfiltrierter Mailbox-Daten genutzt.
XstReader is an open-source tool used to extract the contents of electronic correspondence, likely from email storage files.
Open-source tool used to parse and view Outlook OST/PST archives after extraction, enabling access to full email contents.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.