ToddyCat is a sophisticated cyber espionage group that has targeted high-profile organizations across Europe and Asia since 2020, initially compromising Microsoft Exchange servers in Taiwan and Vietnam using an unidentified vulnerability. The group rapidly expanded its operations in early 2021 by exploiting the ProxyLogon vulnerability, enabling them to move beyond regional targets and establish a global presence. Their campaigns involve deploying multiple malware variants, such as China Chopper web shells, Samurai backdoors, and Ninja Trojan loaders, with later operations introducing advanced tools like TCESB to exploit security products and PowerShell-based credential harvesting scripts. ToddyCat demonstrates a deep understanding of Windows security architecture, employing scheduled tasks, PowerShell commands with bypass flags, and sophisticated defense evasion techniques including BYOVD, DLL side-loading, and reverse SSH tunnels to maintain persistence and avoid detection.
The group’s lateral movement is facilitated through SMB shares, and they use specialized tools like TCSectorCopy to bypass file locks and extract sensitive data, which is then compressed and exfiltrated over command-and-control channels. Their evolving toolkit and operational security measures highlight a continuous adaptation to security defenses, making them a persistent threat to organizations worldwide. Security analysts have mapped ToddyCat’s tactics, techniques, and procedures to MITRE ATT&CK, providing defenders with actionable intelligence to simulate and mitigate these advanced threats.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
By early January 2026, public reporting described ToddyCat as using advanced persistence, defense evasion, credential theft, and data exfiltration techniques, including scheduled tasks, PowerShell policy bypass, browser memory dumping, OAuth token theft, and encrypted exfiltration. Reporting also highlighted newer tooling such as the TCESB utility targeting security product vulnerabilities.
After its initial activity, ToddyCat broadened operations by exploiting the Microsoft Exchange ProxyLogon vulnerability against organizations across Europe and Asia. The campaign used tools including China Chopper web shells, the Samurai backdoor, and Ninja Trojan loaders to establish access and persistence.
ToddyCat activity was observed starting in December 2020, initially compromising Microsoft Exchange servers at high-profile organizations in Taiwan and Vietnam. These early intrusions marked the beginning of the group's known cyber-espionage campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.