The ToddyCat advanced persistent threat (APT) group has evolved its attack methods, shifting focus from browser credential theft to targeting Outlook email archives and Microsoft 365 access tokens. Recent research by Kaspersky highlights the use of new custom tools, such as TCSectorCopy and updated versions of TomBerBil, which enable the group to extract entire email archives and OAuth 2.0 tokens from compromised corporate environments. These tokens can be used to access corporate mail outside the victim's infrastructure, increasing the risk of data exfiltration and unauthorized access.
The updated TomBerBil toolkit, now observed running as a PowerShell variant on domain controllers with privileged access, leverages scheduled tasks and the SMB protocol to collect browser data—including cookies, saved credentials, and history—from remote hosts. By capturing Windows DPAPI encryption keys, ToddyCat can decrypt sensitive information for offline analysis. The group has also exploited vulnerabilities such as CVE-2024-11859 in ESET Command Line Scanner to deliver new malware, further expanding its capabilities to target organizations across Europe and Asia.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Kaspersky publicly reported that ToddyCat had revamped its tooling to steal Outlook email archives and Microsoft 365 access tokens, and shared indicators of compromise such as filenames and paths. Multiple outlets then covered the findings, highlighting the group's updated post-exploitation tradecraft.
As defenders blocked browser-based token extraction, ToddyCat adapted by dumping memory from the Outlook process with Sysinternals ProcDump to recover Microsoft 365 access tokens. This reflected the group's ongoing refinement of techniques to maintain access while evading detection.
In April 2025, ToddyCat exploited CVE-2024-11859 in ESET Command Line Scanner during a campaign to execute malicious modules via trusted processes. The activity showed the group continuing to refresh its malware delivery and evasion methods.
In late 2024 and early 2025, ToddyCat evolved from primarily stealing browser credentials to targeting corporate email data. The group began extracting Outlook OST archives with its TCSectorCopy tool and harvesting Microsoft 365 OAuth tokens, including by using SharpTokenFinder and parsing mail data with XstReader.
Kaspersky observed ToddyCat intrusions between May and June 2024 using a PowerShell-based TomBerBil variant. The malware ran from domain controllers and collected browser artifacts, including DPAPI-related material and Firefox data, to enable offline decryption and credential reuse.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcecsoonline.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.