Kaspersky researchers reported that the ToddyCat APT group is using a new .NET malware tool, Umbrij, to compromise corporate Gmail accounts and other Google resources by abusing Google OAuth flows in Chromium-based browsers. The malware is delivered through DLL sideloading with legitimate executables including BDSubWiz.exe, VSTestVideoRecorder.exe, and GoogleDesktop.exe, and can also persist through masqueraded scheduled tasks. After execution, Umbrij reuses an already authenticated browser profile, launches Chrome or Edge in headless mode with a remote debugging port, and automates account-selection and consent steps to capture an OAuth authorization code.
The attackers then exchange the stolen code for Google access tokens and use the API to access Gmail and other account data while remaining largely invisible to the victim. Researchers named the technique Shadow Token via Remote Debug (STRD) and said it depends on an active Google session already present in the victim’s browser; in some cases the malware also impersonates the user by duplicating an explorer.exe token. Defenders were advised to monitor for DLL sideloading and suspicious Chromium launches using flags such as ```
--remote-debugging-port
--headless

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
On 2021-05-13, Securelist published a report describing ToddyCat's use of the Umbrij .NET malware to abuse Google OAuth flows via Chromium remote debugging and access Gmail and other Google resources. The report named the technique Shadow Token via Remote Debug (STRD) and included detection and mitigation guidance.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
7 references tracked. Mallory keeps watching after this page renders.
kaspersky.ru
Open sourcekaspersky.com
Open sourcethehackernews.com
Open sourcedatabreaches.net
Open sourcesecurelist.ru
Open sourcechromeenterprise.google
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.